Latest CVE Feed
-
5.4
MEDIUMCVE-2023-43876
A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.... Read more
Affected Products : october- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43988
An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 11, 2025
-
5.4
MEDIUMCVE-2018-10806
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4298
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more
- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26688
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2021-36398
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.... Read more
Affected Products : moodle- Published: Mar. 06, 2023
- Modified: Mar. 07, 2025
-
5.4
MEDIUMCVE-2022-0256
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-9465
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-44851
A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter.... Read more
Affected Products : perfex_crm- Published: Sep. 11, 2024
- Modified: Sep. 13, 2024
-
5.4
MEDIUMCVE-2020-4666
IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
Affected Products : engineering_requirements_quality_assistant_on-premises- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36668
Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for fur... Read more
Affected Products : garage_management_system- Published: Sep. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42335
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.... Read more
Affected Products : easytest_online_learning_test_platform- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30172
Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additi... Read more
Affected Products : omnidirectional_communication_system- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1704
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.... Read more
Affected Products : pimcore- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36863
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.... Read more
Affected Products : quiz_and_survey_master- Published: Oct. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5559
The Kids GoldFish Care (aka air.josiane.sauveterre.kidsgoldfishcare) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte... Read more
Affected Products : goldfish_care- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-12849
Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated URL by any unauthenticated or authenticated user.... Read more
Affected Products : cells- Published: Jun. 05, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5578
The Trading 212 FOREX (aka com.avuscapital.trading212) application before 2.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : trading_212_forex- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-1127
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface... Read more
Affected Products : enterprise_nfv_infrastructure_software- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43953
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.... Read more
- Published: Oct. 03, 2023
- Modified: May. 29, 2025