Latest CVE Feed
-
5.4
MEDIUMCVE-2022-29442
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.... Read more
Affected Products : private_messages- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29940
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.... Read more
Affected Products : librehealth_ehr- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19148
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.... Read more
Affected Products : jfinal_cms- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-18840
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.... Read more
Affected Products : semcms- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-5560
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted pack... Read more
- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2022-39270
DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that ... Read more
Affected Products : discotoc- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-39834
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.... Read more
Affected Products : primekey_ejbca- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025
-
5.4
MEDIUMCVE-2020-4364
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34870
Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.... Read more
Affected Products : geode- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2023-25347
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.... Read more
Affected Products : churchcrm- Published: Apr. 25, 2023
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2021-20560
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35174
A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.... Read more
Affected Products : starterkit- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15914
A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to acces... Read more
Affected Products : origin_client- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26260
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.... Read more
Affected Products : oxid_eshop- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2014-3826
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.... Read more
Affected Products : mybb- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36347
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.... Read more
Affected Products : alpine_phototile_for_pinterest- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26952
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.... Read more
Affected Products : onekeyadmin- Published: Mar. 08, 2023
- Modified: Mar. 03, 2025
-
5.4
MEDIUMCVE-2022-36533
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26955
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.... Read more
Affected Products : onekeyadmin- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2262
Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.... Read more
Affected Products : android_lint- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024