Latest CVE Feed
-
5.4
MEDIUMCVE-2022-22417
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to... Read more
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-22436
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru... Read more
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5677
The Point Inside Shopping & Travel (aka com.pointinside.android.app) application 3.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte... Read more
Affected Products : point_inside_shopping_\&_travel- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5688
The Runtastic Pedometer (aka com.runtastic.android.pedometer.lite) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce... Read more
Affected Products : runtastic_pedometer- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-29227
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database ... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2014-7609
The iStunt 2 (aka com.miniclip.istunt2) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : istunt_2- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-25208
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary ... Read more
Affected Products : barangay_management_system- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7661
The Masquito Blogger (aka com.wmasquito) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : masquito_blogger- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-7634
SUAP V2 allows XSS during the update of user information.... Read more
Affected Products : sistema_unificado_de_administracao_publica- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52518
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recomme... Read more
- Published: Nov. 15, 2024
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2014-5811
The ZOOM Cloud Meetings (aka us.zoom.videomeetings) application @7F060008 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-31296
Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81. ... Read more
Affected Products : bookingpress- Published: Apr. 07, 2024
- Modified: Mar. 20, 2025
-
5.4
MEDIUMCVE-2024-3190
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitizatio... Read more
- Published: May. 30, 2024
- Modified: Jan. 30, 2025
-
5.4
MEDIUMCVE-2024-31898
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.... Read more
Affected Products : infosphere_information_server- Published: Jun. 30, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5935
The Daily Free App @ Amazon (aka com.kattanweb.android.dfaa) application 1.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : daily_free_app_\@_amazon- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-3288
The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks... Read more
- Published: Jun. 07, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-54936
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
5.4
MEDIUMCVE-2014-5963
The Halieutics (aka com.corn.Halieutics) application 21.40.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : halieutics- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-13077
A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/add-property.php. The manipulation of the argument Land Subtype leads to cross site scripting. It is p... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
5.4
MEDIUMCVE-2024-33636
Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1. ... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024