Latest CVE Feed
-
5.4
MEDIUMCVE-2023-35020
IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 25... Read more
- Published: Jan. 19, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3372
The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stor... Read more
Affected Products : lana_shortcodes- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2015-7423
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM... Read more
Affected Products : infosphere_master_data_management- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7682
The GR8! TV (aka com.magzter.greighttv) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : gr8\!_tv- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-3510
The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloa... Read more
Affected Products : ftp_access- Published: Sep. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-22402
IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session... Read more
- Published: Sep. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1762
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially ... Read more
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40678
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.... Read more
Affected Products : piwigo- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-6734
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected device, ... Read more
Affected Products : identity_services_engine- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-4661
The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contrib... Read more
Affected Products : widgets_for_woocommerce_products_on_elementor- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
5.4
MEDIUMCVE-2018-16484
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.... Read more
Affected Products : m-server- Published: Feb. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25915
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.... Read more
Affected Products : thinkcmf- Published: Aug. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1658
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could e... Read more
Affected Products : rational_collaborative_lifecycle_management- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7015
The JJ Texas Hold'em Poker (aka cn.jj.poker) application 1.13.23.HD for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jj_texas_hold\'em_poker- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6816
The WISDOM (aka lvtu99.com.nescmxiaoniuniu) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : wisdom- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6689
The JW Cards (aka com.jingwei.card) application 3.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jw_cards- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5632
The Mega Jump (aka com.getsetgames.megajump) application @7F080002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : mega_jump- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5962
The Guess The Actor (aka com.gamelikeinc.actors) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : guess_the_actor- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5919
The SurDoc - 100GB+ FREE storage (aka com.jd.surdoc) application 1.3.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : surdoc_-_100gb\+_free_storage- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-17542
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.... Read more
Affected Products : dotcms- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024