Latest CVE Feed
-
5.4
MEDIUMCVE-2024-53365
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.... Read more
Affected Products : vehicle_parking_management_system- Published: Nov. 26, 2024
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2024-31985
XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictable URL... Read more
Affected Products : xwiki- Published: Apr. 10, 2024
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2024-32097
Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1. ... Read more
Affected Products : geo_my_wordpress- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-40753
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a... Read more
- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-32239
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in xtemos WoodMart theme <= 7.2.1 versions.... Read more
- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7754
The Condor S.E. (aka com.app_condorsoutheast.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : condor_s.e.- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5921
The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : need_for_speed_network- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5933
The Coke Studio 7 (aka com.cokeshare.pakistan) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : cokestudio7- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-40844
In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL b... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
5.4
MEDIUMCVE-2014-5943
The LabMSF Antivirus beta (aka com.ReSync.RNGN) 1.0.2 application Beta for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : labmsf_antivirus_beta- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-54935
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
5.4
MEDIUMCVE-2022-40975
Missing Authorization vulnerability in Aazztech Post Slider.This issue affects Post Slider: from n/a through 1.6.7. ... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-34814
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.29. ... Read more
Affected Products : unyson- Published: May. 14, 2024
- Modified: Mar. 20, 2025
-
5.4
MEDIUMCVE-2024-5942
The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authen... Read more
Affected Products : page_and_post_clone- Published: Jun. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31941
Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-6370
A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknown functionality of the file /labvantage/rc?command=file&file=WEB-OPAL/pagetypes/bulletins/sendbulletin.jsp of the component POST Reques... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-41312
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP reque... Read more
- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35362
Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.... Read more
Affected Products : ecshop- Published: May. 22, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-33210
A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.... Read more
Affected Products : flatpress- Published: Oct. 02, 2024
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2024-7793
A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-task.php. The manipulation of the argument task_name leads to ... Read more
Affected Products : task_progress_tracker- Published: Aug. 14, 2024
- Modified: Aug. 19, 2024