Latest CVE Feed
-
5.4
MEDIUMCVE-2024-35351
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name results in cross-site scripting.... Read more
Affected Products : dino_physics_school_assistant- Published: May. 30, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2019-4653
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19203
An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42943
Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter.... Read more
Affected Products : ipplan- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14926
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.... Read more
Affected Products : cms_made_simple- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-28875
A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.... Read more
Affected Products : filerun- Published: Dec. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5796
The Chest Workout (aka net.p4p.chest) application 2.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : chest_workout- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-48866
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6710
The Chifro Kids Coloring Game (aka com.chifro.kids_coloring_game) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer... Read more
Affected Products : chifro_kids_coloring_game- Published: Sep. 25, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6905
The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : h2o_human_harmony_organization- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7364
The Promotional Items (aka com.wPromotionalItems) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : promotional_items- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7686
The So. Co. Business Partnership (aka com.ChamberMe.SCBPSOUTHERNCO) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted c... Read more
Affected Products : so._co._business_partnership- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-19968
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content... Read more
Affected Products : pandora_fms- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-3931
Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to inject arbitrary web script or HTML via the property_name parameter, related... Read more
Affected Products : jomres- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31375
Missing Authorization vulnerability in Saleswonder.Biz Team WP2LEADS.This issue affects WP2LEADS: from n/a through 3.2.7. ... Read more
Affected Products :- Published: Apr. 08, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7655
The Dresden Transport Museum (aka de.appack.project.vmd) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dresden_transport_museum- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-1115
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153.... Read more
Affected Products : campaign- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5683
The Piano Teacher (aka com.rubycell.pianisthd) application 20140730 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : piano_teacher- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-15038
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.... Read more
Affected Products : coming_soon_page\,_under_construction_\&_maintenance_mode- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7640
The Hotel Room (aka com.wHotelRoom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : hotel_room- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025