Latest CVE Feed
-
5.4
MEDIUMCVE-2021-38151
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.... Read more
Affected Products : patient_management_system- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25585
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.... Read more
Affected Products : unioncms- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25774
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Sep. 23, 2024
-
5.4
MEDIUMCVE-2021-38883
IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun... Read more
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26146
Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker.... Read more
Affected Products : qtest- Published: Feb. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33850
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.... Read more
Affected Products : clarity- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39609
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.... Read more
Affected Products : flatcore-cms- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2729
Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.... Read more
Affected Products : openemr- Published: Aug. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5515
Cross-site scripting (XSS) vulnerability in the user prompt function in GeniXCMS through 0.0.8 allows remote authenticated users to inject arbitrary web script or HTML via tag names.... Read more
Affected Products : genixcms- Published: Jan. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-5691
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.... Read more
- Published: Jan. 14, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41142
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. There is a cross-site scripting vulnerability in Tuleap Community Edition prior to 12.11.99.25 and Tuleap Enterprise Edition 12.11-2. A mal... Read more
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2872
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.... Read more
Affected Products : octoprint- Published: Sep. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42061
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data fr... Read more
Affected Products : businessobjects_business_intelligence_platform- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29442
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.... Read more
Affected Products : private_messages- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29940
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.... Read more
Affected Products : librehealth_ehr- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19148
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.... Read more
Affected Products : jfinal_cms- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-18840
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.... Read more
Affected Products : semcms- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-5560
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted pack... Read more
- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2022-39270
DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that ... Read more
Affected Products : discotoc- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-39834
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.... Read more
Affected Products : primekey_ejbca- Published: Nov. 17, 2022
- Modified: Apr. 29, 2025