Latest CVE Feed
-
5.4
MEDIUMCVE-2020-4546
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager rational_rhapsody_design_manager rational_team_concert doors_next engineering_test_management engineering_workflow_management engineering_requirements_management_doors_next +1 more products- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1408
IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred... Read more
Affected Products : rational_team_concert- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-5039
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivate... Read more
- Published: Dec. 30, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2020-4755
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : spectrum_scale- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5294
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0... Read more
Affected Products : prestashop_socialfollow- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.... Read more
Affected Products : pfsense- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5570
Cross-site scripting vulnerability in Sales Force Assistant version 11.2.48 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : sales_force_assistant- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6222
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6643
An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS).... Read more
Affected Products : fortiisolator- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8145
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.... Read more
Affected Products : magento- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0322
Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document.... Read more
Affected Products : connections- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-8778
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.... Read more
Affected Products : alfresco- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15033
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget.php ip parameter.... Read more
Affected Products : nedi- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7944
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authe... Read more
Affected Products : magento- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9461
Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-5899
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : jazz_reporting_service- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-1718
IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : sterling_b2b_integrator- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24680
The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users with a role as low as editor to perform Stored Cross-Site Scripting attacks, e... Read more
Affected Products : wp_travel_engine- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44608
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.... Read more
Affected Products : bloofoxcms- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024