Latest CVE Feed
-
5.4
MEDIUMCVE-2022-4562
The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Script... Read more
Affected Products : meks_flexible_shortcodes- Published: Feb. 13, 2023
- Modified: Mar. 20, 2025
-
5.4
MEDIUMCVE-2022-4747
The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored C... Read more
Affected Products : download_post_category_image_with_grid_and_slider- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2014-5948
The Obama for America (aka com.barackobama.ofa) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : obama_for_america- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5965
The GrooveMusic (aka com.mobincube.android.sc_2HKFF) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : groovemusic- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-6046
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-6011
The cutprice (aka kr.co.wedoit.cutprice) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : cutprice- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7563
The Tactical Force LLC (aka com.conduit.app_69f61a8852b046f2846054b30c4032a7.app) application 1.9.23.276 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inform... Read more
Affected Products : tactical_force_llc- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1439
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading... Read more
Affected Products : rational_quality_manager- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5927
The FastCustomer -- Fast Customer (aka www.fastcustomer.com) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : fastcustomer_--_fast_customer- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-24662
SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM RP 3.1.0.... Read more
Affected Products : transaction_lifecycle_management_reconciliations-premium- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1827
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre... Read more
- Published: Jun. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1522
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading... Read more
Affected Products : rational_quality_manager- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35351
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name results in cross-site scripting.... Read more
Affected Products : dino_physics_school_assistant- Published: May. 30, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2019-4653
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19203
An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42943
Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter.... Read more
Affected Products : ipplan- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14926
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.... Read more
Affected Products : cms_made_simple- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-28875
A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.... Read more
Affected Products : filerun- Published: Dec. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5796
The Chest Workout (aka net.p4p.chest) application 2.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : chest_workout- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-48866
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024