Latest CVE Feed
-
5.4
MEDIUMCVE-2014-7071
The Autocar India (aka com.magzter.autocarindia) application 3.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : autocar_india- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7052
The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific... Read more
Affected Products : sahab-alkher.com- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7075
The HAPPY (aka com.tw.knowhowdesign.sinfonghuei) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : happy- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7368
The Compassion Satisfaction (aka com.wCompassionSatisfactionWorkshopPresentation) application 0.75.13440.35155 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive ... Read more
Affected Products : compassion_satisfaction- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7402
The SK encar (aka com.encardirect.app) application @7F050000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : sk_encar- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7459
The Press-Leader (aka com.soln.S95309F65AD59F99CFC2C710A517B0B7E) application 1.0011.b0011 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr... Read more
Affected Products : press-leader- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7802
The Top Roller Coasters Europe 2 (aka com.appaapps.top10tallesteuropeanrollercoasters2) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive i... Read more
Affected Products : top_roller_coasters_europe_2- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-0382
A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.35
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-17904
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.... Read more
Affected Products : lynda_clone- EPSS Score: %0.19
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2011-1625
Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," ... Read more
Affected Products : ios- EPSS Score: %0.33
- Published: Aug. 18, 2011
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2012-5044
Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a denial of service (media loops and stack memory corruption) via VoIP traffic, aka Bug ID CSCub45809.... Read more
Affected Products : ios- EPSS Score: %0.43
- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-6953
The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body and footer content parameters in all versions up to, and including, 1.1.7 due to insufficient input san... Read more
Affected Products : pdf_generator_for_fluent_forms- EPSS Score: %0.27
- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-1030
A vulnerability was found in Cogites eReserv 7.7.58. It has been classified as problematic. This affects an unknown part of the file /front/admin/tenancyDetail.php. The manipulation of the argument id leads to cross site scripting. It is possible to initi... Read more
Affected Products : ereserv- EPSS Score: %0.06
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43994
An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- EPSS Score: %0.08
- Published: Jan. 24, 2024
- Modified: Jun. 16, 2025
-
5.4
MEDIUMCVE-2017-1168
IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.27
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-33943
Authenticated (contributor or higher user role) Cross-Site Scripting (XSS) vulnerability in Nico Amarilla's BxSlider WP plugin <= 2.0.0 at WordPress.... Read more
Affected Products : bxslider_wp- EPSS Score: %0.18
- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-27105
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.... Read more
Affected Products : inmailx- EPSS Score: %0.47
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7670
The Motor Town: Machine Soul Free (aka com.alawar.motortownfree) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : motor_town\- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7723
The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : carnegie_mellon_silicon_valley- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-41157
Multiple stored cross-site scripting (XSS) vulnerabilities in Usermin 2.000 allow remote attackers to inject arbitrary web script or HTML via the folder name parameter while creating the folder to manage the folder tab, filter tab, and forward mail tab.... Read more
Affected Products : usermin- EPSS Score: %0.09
- Published: Sep. 16, 2023
- Modified: Nov. 21, 2024