Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-39270

    DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that ... Read more

    Affected Products : discotoc
    • Published: Oct. 06, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-39834

    A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.... Read more

    Affected Products : primekey_ejbca
    • Published: Nov. 17, 2022
    • Modified: Apr. 29, 2025
  • 5.4

    MEDIUM
    CVE-2020-4364

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more

    • Published: Jul. 14, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-34870

    Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.... Read more

    Affected Products : geode
    • Published: Oct. 25, 2022
    • Modified: May. 09, 2025
  • 5.4

    MEDIUM
    CVE-2023-25347

    A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.... Read more

    Affected Products : churchcrm
    • Published: Apr. 25, 2023
    • Modified: Feb. 04, 2025
  • 5.4

    MEDIUM
    CVE-2021-20560

    IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h... Read more

    • Published: Jul. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-35174

    A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.... Read more

    Affected Products : starterkit
    • Published: Aug. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-15914

    A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to acces... Read more

    Affected Products : origin_client
    • Published: Nov. 02, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-26260

    OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.... Read more

    Affected Products : oxid_eshop
    • Published: Apr. 11, 2023
    • Modified: Feb. 11, 2025
  • 5.4

    MEDIUM
    CVE-2014-3826

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.... Read more

    Affected Products : mybb
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-36347

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.... Read more

    Affected Products : alpine_phototile_for_pinterest
    • Published: Aug. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-26952

    onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.... Read more

    Affected Products : onekeyadmin
    • Published: Mar. 08, 2023
    • Modified: Mar. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-36533

    Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.... Read more

    Affected Products : linux_kernel syncovery
    • Published: Sep. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-26955

    onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.... Read more

    Affected Products : onekeyadmin
    • Published: Mar. 07, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-2262

    Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.... Read more

    Affected Products : android_lint
    • Published: Sep. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-2316

    Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.... Read more

    Affected Products : static_analysis_utilities
    • Published: Nov. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-38704

    Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.... Read more

    Affected Products : seo_redirection
    • Published: Sep. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-38790

    Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in W... Read more

    Affected Products : gitops
    • Published: Sep. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4392

    The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ... Read more

    • Published: Jan. 09, 2023
    • Modified: Apr. 09, 2025
  • 5.4

    MEDIUM
    CVE-2022-44071

    Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.... Read more

    Affected Products : zenario
    • Published: Nov. 16, 2022
    • Modified: Apr. 30, 2025
Showing 20 of 293559 Results