Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-1759

    The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : rb_internal_links
    • Published: Jun. 13, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-1776

    The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    • Published: Jun. 27, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-6757

    The Koran - AlqoranVideos (aka com.alqoran.videos.example) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more

    Affected Products : koran_-_alqoranvideos
    • Published: Sep. 28, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2023-52265

    IDURAR (aka idurar-erp-crm) through 2.0.1 allows stored XSS via a PATCH request with a crafted JSON email template in the /api/email/update data.... Read more

    Affected Products : idurar idurar
    • Published: Dec. 30, 2023
    • Modified: Apr. 17, 2025
  • 5.4

    MEDIUM
    CVE-2023-5237

    The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting... Read more

    Affected Products : memberlite_shortcodes
    • Published: Oct. 31, 2023
    • Modified: Apr. 22, 2025
  • 5.4

    MEDIUM
    CVE-2021-24567

    The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.... Read more

    Affected Products : simple_post
    • Published: Jan. 16, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-46025

    A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.... Read more

    Affected Products : oneblog
    • Published: Jan. 19, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-5286

    A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected by this issue is some unknown functionality of the file add_category.php of the component Category Handler. The manipulation of the arg... Read more

    Affected Products : expense_tracker
    • Published: Sep. 29, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-5793

    A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCreateForm of the file /core/tools/customblock.php of the component Dashboard. The manipulation of the argument customblock_place leads t... Read more

    Affected Products : fluisity flusity
    • Published: Oct. 26, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-4888

    The BattleFriends at Sea GOLD (aka com.tequilamobile.warshipslivegold) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craf... Read more

    Affected Products : battlefriends_at_sea_gold
    • Published: Oct. 21, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-3612

    A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file barang.php. The manipulation of the argument nama_barang/merek leads t... Read more

    Affected Products : warehouse_management_system
    • Published: Apr. 11, 2024
    • Modified: Feb. 18, 2025
  • 5.4

    MEDIUM
    CVE-2024-1171

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 du... Read more

    Affected Products : essential_addons_for_elementor
    • Published: Feb. 29, 2024
    • Modified: Jan. 08, 2025
  • 5.4

    MEDIUM
    CVE-2024-37803

    Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the S... Read more

    • Published: Jun. 18, 2024
    • Modified: Mar. 18, 2025
  • 5.4

    MEDIUM
    CVE-2021-22524

    Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4... Read more

    Affected Products : access_manager netiq_access_manager
    • Published: Sep. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-37250

    Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.... Read more

    Affected Products : craft_cms
    • Published: Sep. 16, 2022
    • Modified: Jun. 03, 2025
  • 5.4

    MEDIUM
    CVE-2024-38507

    In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible... Read more

    Affected Products : hub
    • Published: Jun. 18, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-38503

    When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Request... Read more

    Affected Products : syncope
    • Published: Jul. 22, 2024
    • Modified: Dec. 06, 2024
  • 5.4

    MEDIUM
    CVE-2024-39094

    Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.... Read more

    Affected Products : friendica
    • Published: Aug. 20, 2024
    • Modified: Mar. 13, 2025
  • 5.4

    MEDIUM
    CVE-2014-6909

    The Coca-Cola FM Peru (aka com.enyetech.radio.coca_cola.fm_pe) application 2.0.41716 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ... Read more

    Affected Products : coca-cola_fm_peru
    • Published: Oct. 04, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2023-7136

    A vulnerability classified as problematic was found in code-projects Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /main/doctype.php of the component Document Type Handler. The manipulation of the arg... Read more

    Affected Products : record_management_system
    • Published: Dec. 28, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 293517 Results