Latest CVE Feed
-
5.4
MEDIUMCVE-2022-40001
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2022-3984
The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripti... Read more
Affected Products : flowplayer_video_player- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2022-40047
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.... Read more
Affected Products : flatpress- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3958
Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted... Read more
Affected Products : bluespice- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3704
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible ... Read more
- Published: Oct. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3853
Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by including malicious code in a legitimate web page or web application.... Read more
Affected Products : supra-csv-parser- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-3716
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name/Midd... Read more
Affected Products : online_medicine_ordering_system- Published: Oct. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3505
A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is poss... Read more
Affected Products : sanitization_management_system- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3587
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component My Account. The manipulation of the argument First Name... Read more
Affected Products : simple_cold_storage_management_system- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3453
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /transcation.php. The manipulation of the argument buyer_name leads to cross site script... Read more
Affected Products : book_store_management_system- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3562
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.... Read more
Affected Products : librenms- Published: Nov. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3338
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and pass... Read more
Affected Products : epolicy_orchestrator- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3326
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.... Read more
Affected Products : rdiffweb- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3201
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium sec... Read more
- Published: Sep. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3096
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators... Read more
Affected Products : wp_total_hacks- Published: Oct. 31, 2022
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2019-16310
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.... Read more
Affected Products : niushop- Published: Sep. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16523
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-39348
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescape... Read more
- Published: Oct. 26, 2022
- Modified: Nov. 25, 2024
-
5.4
MEDIUMCVE-2022-39350
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Due to the common practice of providing v... Read more
Affected Products : dependency-track_frontend- Published: Oct. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-39291
ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. This ... Read more
Affected Products : zoneminder- Published: Oct. 07, 2022
- Modified: Nov. 21, 2024