Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2018-7303

    The Calendar component in Tiki 17.1 allows HTML injection.... Read more

    Affected Products : tikiwiki_cms\/groupware
    • Published: Feb. 21, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1000177

    A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control file names of uploaded files to define file names conta... Read more

    Affected Products : s3_publisher
    • Published: May. 08, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1000604

    A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another... Read more

    Affected Products : badge
    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-9172

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.... Read more

    Affected Products : wordpress_file_upload
    • Published: Apr. 01, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10726

    A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/c... Read more

    Affected Products : yellow
    • Published: May. 04, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-7331

    The TodaysSeniorsNetwork (aka com.wTodaysSeniorsNetwork) application 0.21.13245.84038 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted... Read more

    Affected Products : todaysseniorsnetwork
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7333

    The Aloha Guide (aka com.aloha.guide.japnese) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : aloha_guide
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2019-0262

    SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more

    Affected Products : businessobjects_bi_platform
    • Published: Feb. 15, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-7441

    The Pakan Ken Tube (aka com.PakanKen) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : pakan_ken_tube
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2019-10396

    Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions.... Read more

    Affected Products : dashboard_view
    • Published: Sep. 12, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-12903

    In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title ... Read more

    Affected Products : endpoint_privilege_manager
    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1363

    IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more

    Affected Products : jazz_reporting_service
    • Published: Apr. 25, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-11368

    Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.... Read more

    Affected Products : solar_data_recorder
    • Published: Jun. 03, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-7508

    The Help For Doc (aka com.childrens.physician.relations) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : help_for_doc
    • Published: Oct. 20, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2018-1395

    IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading... Read more

    Affected Products : rational_quality_manager
    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-9547

    admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page t... Read more

    Affected Products : bigtree_cms
    • Published: Jun. 12, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2019-13070

    A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agent/action_recipient Event Action/Rec... Read more

    Affected Products : powerpanel
    • Published: Jul. 09, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-16624

    panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.... Read more

    Affected Products : kirby
    • Published: May. 13, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-16728

    feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.... Read more

    Affected Products : feindura
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-15451

    A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is du... Read more

    Affected Products : prime_service_catalog
    • Published: Nov. 08, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292815 Results