Latest CVE Feed
-
5.4
MEDIUMCVE-2022-38390
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
Affected Products : business_automation_workflow- Published: Nov. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24388
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).... Read more
Affected Products : booking_calendar- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-15395
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this... Read more
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20357
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager rational_rhapsody_design_manager rational_team_concert rhapsody_model_manager collaborative_lifecycle_management engineering_insights engineering_lifecycle_management +6 more products- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3935
The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks... Read more
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2020-4360
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : planning_analytics_local- Published: Jun. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34537
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-20696
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.... Read more
Affected Products : gila_cms- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3628
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.... Read more
Affected Products : openkm- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20746
Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : wordpress_popular_posts- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4426
The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun... Read more
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-41785
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions.... Read more
Affected Products : gallery_images_ape- Published: Mar. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42099
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.... Read more
Affected Products : klik- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-42205
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.... Read more
- Published: Oct. 21, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2020-2219
Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission, resulting in a stored cross-site scripting vulnerability.... Read more
Affected Products : link_column- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4596
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr... Read more
Affected Products : sterling_b2b_integrator- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42236
A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.... Read more
Affected Products : merchandise_online_store- Published: Oct. 11, 2022
- Modified: May. 20, 2025
-
5.4
MEDIUMCVE-2020-2317
Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step... Read more
Affected Products : findbugs- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1933
IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : planning_analytics- Published: May. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23654
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."... Read more
Affected Products : navigatecms- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024