Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-43871

    A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).... Read more

    Affected Products : wbce_cms
    • EPSS Score: %0.21
    • Published: Sep. 28, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-9120

    In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post.... Read more

    Affected Products : crea8social
    • EPSS Score: %0.19
    • Published: Mar. 29, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0995

    Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.... Read more

    Affected Products : bumsys business_management_system
    • EPSS Score: %0.09
    • Published: Feb. 24, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-2619

    The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-le... Read more

    • Published: May. 16, 2024
    • Modified: Jan. 29, 2025
  • 5.4

    MEDIUM
    CVE-2018-9155

    Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Man... Read more

    Affected Products : open-audit open-audit
    • EPSS Score: %0.20
    • Published: Apr. 12, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-28522

    ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.... Read more

    Affected Products : zcms
    • EPSS Score: %0.20
    • Published: Apr. 26, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-1117

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.... Read more

    Affected Products : pimcore
    • EPSS Score: %0.00
    • Published: Mar. 01, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43718

    Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and v... Read more

    Affected Products : superset
    • EPSS Score: %0.83
    • Published: Jan. 16, 2023
    • Modified: Apr. 07, 2025
  • 5.4

    MEDIUM
    CVE-2022-28599

    A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a ... Read more

    Affected Products : fuel_cms
    • EPSS Score: %0.25
    • Published: May. 03, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36695

    Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.... Read more

    Affected Products : deskpro
    • EPSS Score: %0.21
    • Published: Sep. 08, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4775

    A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to inject malicious scripts into web applications for the purpose of running unwanted actions on the end user's... Read more

    Affected Products : curam_social_program_management
    • EPSS Score: %0.11
    • Published: Oct. 12, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2013-3039

    IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.... Read more

    Affected Products : rational_requirements_composer
    • EPSS Score: %0.08
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 5.4

    MEDIUM
    CVE-2022-37430

    Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).... Read more

    Affected Products : framework
    • EPSS Score: %0.32
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-1067

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.... Read more

    Affected Products : pimcore
    • EPSS Score: %0.00
    • Published: Feb. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-12745

    out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.... Read more

    Affected Products : seeddms
    • EPSS Score: %0.33
    • Published: Jun. 20, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-4514

    The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more

    Affected Products : mmm_simple_file_list
    • EPSS Score: %0.12
    • Published: Nov. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-12683

    Katyshop2 before 2.12 has multiple stored XSS issues.... Read more

    Affected Products : katyshop2
    • EPSS Score: %0.21
    • Published: May. 07, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-12718

    In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.... Read more

    Affected Products : phpfusion php-fusion
    • EPSS Score: %0.31
    • Published: May. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-15284

    Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the cont... Read more

    Affected Products : october
    • EPSS Score: %2.98
    • Published: Oct. 12, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2014-5525

    The MoMinis library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : mominis_library
    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
Showing 20 of 291915 Results