Latest CVE Feed
-
5.4
MEDIUMCVE-2023-27864
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-F... Read more
- Published: Apr. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-23190
Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure u... Read more
- Published: Apr. 08, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5617
The Exsoul Web Browser (aka com.exsoul) application 3.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : exsoul_web_browser- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-5004
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : cm_popup- Published: Jul. 22, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2840
The Enhanced Media Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload functionality in all versions up to, and including, 2.8.9 due to the plugin allowing 'dfxp' files to be uploaded. This makes it possible for auth... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5662
The Rail Rush (aka com.miniclip.railrush) application 1.9.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : rail_rush- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-24060
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.... Read more
Affected Products : springboot-manager- Published: Feb. 01, 2024
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2014-5731
The Word Search (aka com.virtuesoft.wordsearch) application 2.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : word_search- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-35418
Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.... Read more
Affected Products : group_office- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-51463
IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.... Read more
- Published: Dec. 21, 2024
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2014-7617
The www.roads365.com (aka ydx.android) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : www.roads365.com- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-25874
A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Create Tag text field.... Read more
Affected Products : enhavo- Published: Feb. 22, 2024
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2014-5804
The Mail.Ru Dating (aka ru.mail.love) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : mail.ru_dating- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5816
The MeiPai (aka com.meitu.meipaimv) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : meipai- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5843
The ADP AGENCY Immobiliare (aka com.wAdpagencyAndroid) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : adp_agency_immobiliare- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-53365
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.... Read more
Affected Products : vehicle_parking_management_system- Published: Nov. 26, 2024
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2024-31985
XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictable URL... Read more
Affected Products : xwiki- Published: Apr. 10, 2024
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2024-32097
Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1. ... Read more
Affected Products : geo_my_wordpress- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-40753
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a... Read more
- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-32239
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in xtemos WoodMart theme <= 7.2.1 versions.... Read more
- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024