Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-2219

    Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission, resulting in a stored cross-site scripting vulnerability.... Read more

    Affected Products : link_column
    • Published: Jul. 02, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-4596

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr... Read more

    Affected Products : sterling_b2b_integrator
    • Published: Feb. 26, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-42236

    A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.... Read more

    Affected Products : merchandise_online_store
    • Published: Oct. 11, 2022
    • Modified: May. 20, 2025
  • 5.4

    MEDIUM
    CVE-2020-2317

    Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step... Read more

    Affected Products : findbugs
    • Published: Nov. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1933

    IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more

    Affected Products : planning_analytics
    • Published: May. 01, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-23654

    NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."... Read more

    Affected Products : navigatecms
    • Published: Aug. 26, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-4663

    IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more

    Affected Products : websphere_application_server
    • Published: Dec. 10, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1549

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the... Read more

    Affected Products : rational_quality_manager
    • Published: Jul. 10, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-44960

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into t... Read more

    Affected Products : webtareas
    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2022-40204

    A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.... Read more

    • Published: Dec. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-40317

    OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.... Read more

    Affected Products : openkm
    • Published: Sep. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-30452

    The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map with the hyperlink parameter.... Read more

    Affected Products : easymind
    • Published: May. 17, 2023
    • Modified: Jan. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-45892

    In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.... Read more

    Affected Products : planet_estream
    • Published: Dec. 25, 2022
    • Modified: Apr. 14, 2025
  • 5.4

    MEDIUM
    CVE-2021-21358

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user accoun... Read more

    Affected Products : typo3
    • Published: Mar. 23, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-30736

    Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.... Read more

    Affected Products : samsung_assistant assistant
    • Published: Oct. 04, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4624

    The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more

    Affected Products : gs_logo_slider
    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2023-32061

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulne... Read more

    Affected Products : discourse
    • Published: Jun. 13, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4753

    The Print-O-Matic WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : print-o-matic
    • Published: Jan. 23, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-34297

    Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.... Read more

    Affected Products : gii
    • Published: Dec. 09, 2022
    • Modified: Apr. 22, 2025
  • 5.4

    MEDIUM
    CVE-2020-13889

    showAlert() in the administration panel in Bludit 3.12.0 allows XSS.... Read more

    Affected Products : bludit
    • Published: Jun. 06, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 292815 Results