Latest CVE Feed
-
5.4
MEDIUM- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0322
Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document.... Read more
Affected Products : connections- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-8778
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.... Read more
Affected Products : alfresco- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15033
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget.php ip parameter.... Read more
Affected Products : nedi- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7944
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authe... Read more
Affected Products : magento- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9461
Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-5899
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : jazz_reporting_service- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-1718
IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : sterling_b2b_integrator- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24680
The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users with a role as low as editor to perform Stored Cross-Site Scripting attacks, e... Read more
Affected Products : wp_travel_engine- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44608
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.... Read more
Affected Products : bloofoxcms- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24961
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting at... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2011-2586
The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.... Read more
Affected Products : ios- Published: May. 02, 2012
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2021-20352
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1563
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p... Read more
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27679
Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.... Read more
Affected Products : batflat- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0157
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-0013
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context... Read more
Affected Products : ember.js- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0822
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.... Read more
Affected Products : orchardcore- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0832
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.... Read more
Affected Products : pimcore- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-2345
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privilege... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024