Latest CVE Feed
-
5.4
MEDIUMCVE-2019-18636
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.... Read more
Affected Products : .net_forum- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19085
A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.... Read more
Affected Products : server- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-27990
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).... Read more
Affected Products : nagios_xi- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28047
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' param... Read more
Affected Products : audimexee- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7544
An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name Field.... Read more
Affected Products : mywebsql- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28409
The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.... Read more
Affected Products : dundas_bi- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7881
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).... Read more
Affected Products : magento- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28647
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the co... Read more
Affected Products : moveit_transfer- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8138
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by s... Read more
Affected Products : magento- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8439
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.... Read more
Affected Products : dilicms- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-20575
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).... Read more
Affected Products : android- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36553
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jul. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4303
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4409
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name retu... Read more
Affected Products : traveler- Published: Oct. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-3997
VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.... Read more
Affected Products : horizon- Published: Oct. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4268
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4645
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
- Published: Jul. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Feb. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5747
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.... Read more
Affected Products : tcexam- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14388
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.... Read more
Affected Products : joyplus-cms- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024