Latest CVE Feed
-
5.4
MEDIUMCVE-2017-1168
IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.27
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-33943
Authenticated (contributor or higher user role) Cross-Site Scripting (XSS) vulnerability in Nico Amarilla's BxSlider WP plugin <= 2.0.0 at WordPress.... Read more
Affected Products : bxslider_wp- EPSS Score: %0.18
- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-27105
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.... Read more
Affected Products : inmailx- EPSS Score: %0.47
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7670
The Motor Town: Machine Soul Free (aka com.alawar.motortownfree) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : motor_town\- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7723
The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : carnegie_mellon_silicon_valley- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-41157
Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab.... Read more
Affected Products : usermin- EPSS Score: %0.09
- Published: Sep. 16, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-42371
Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component.... Read more
Affected Products : rich_text_editor- EPSS Score: %0.38
- Published: Sep. 18, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40577
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.... Read more
Affected Products : online_enrollment_management_system- EPSS Score: %0.19
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7719
The BASEBALL MANAGER K (aka com.cjenm.yagamkgoogle) application 1.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : baseball_manager_k- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7715
The GIGA HOBBY (aka com.innopage.store.gigahobby) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : giga_hobby- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7708
The Raven - The Culture Lover (aka com.booksbyraven) application 1.60 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : raven_-_the_culture_lover- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-20349
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.... Read more
Affected Products : wtcms- EPSS Score: %0.26
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1657
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- EPSS Score: %0.23
- Published: Jan. 04, 2019
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2014-5529
The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : gameloft_library- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5739
The Garfield's Diner (aka com.webprancer.google.GarfieldsDiner) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer... Read more
Affected Products : garfield\'s_diner- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6702
The StarSat International (aka com.conduit.app_b15a1814d2d840198e70e3c235af5e8b.app) application 1.41.54.9222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive i... Read more
Affected Products : starsat_international- EPSS Score: %0.04
- Published: Sep. 25, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-16726
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.... Read more
Affected Products : razorcms- EPSS Score: %0.19
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6686
The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : zoho_books_-_accounting_app- EPSS Score: %0.04
- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6651
The Planet of the Vapes Forum (aka com.tapatalk.planetofthevapescoukforums) application 3.7.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a... Read more
Affected Products : planet_of_the_vapes_forum- EPSS Score: %0.04
- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5696
The Sonic 4 Episode II LITE (aka com.sega.sonic4ep2lite) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : sonic_4_episode_ii_lite- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025