Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-4449

    The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more

    Affected Products : page_scroll_to_id
    • Published: Jan. 16, 2023
    • Modified: Apr. 07, 2025
  • 5.4

    MEDIUM
    CVE-2022-4251

    A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some unknown functionality of the file editBooking.php. The manipulation leads to cross site scripting. The attack may be launched remotely. ... Read more

    Affected Products : movie_ticket_booking_system
    • Published: Dec. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4353

    A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has b... Read more

    Affected Products : pb-cms
    • Published: Dec. 08, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4067

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.... Read more

    Affected Products : librenms
    • Published: Nov. 20, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-1540

    IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more

    • Published: Jan. 26, 2018
    • Modified: Feb. 05, 2025
  • 5.4

    MEDIUM
    CVE-2017-14921

    Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.... Read more

    Affected Products : tine_2.0
    • Published: Sep. 30, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2022-48427

    In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible... Read more

    Affected Products : teamcity
    • Published: Mar. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-48426

    In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible... Read more

    Affected Products : teamcity
    • Published: Mar. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-48013

    Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into t... Read more

    Affected Products : opencats
    • Published: Jan. 27, 2023
    • Modified: Mar. 28, 2025
  • 5.4

    MEDIUM
    CVE-2022-48010

    LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts ... Read more

    Affected Products : limesurvey
    • Published: Jan. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-48178

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.... Read more

    Affected Products : x2crm
    • Published: Apr. 15, 2023
    • Modified: Feb. 06, 2025
  • 5.4

    MEDIUM
    CVE-2022-48007

    A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User-Agent.... Read more

    Affected Products : piwigo
    • Published: Jan. 27, 2023
    • Modified: Mar. 28, 2025
  • 5.4

    MEDIUM
    CVE-2022-48085

    Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.... Read more

    Affected Products : softr
    • Published: Feb. 06, 2023
    • Modified: Mar. 26, 2025
  • 5.4

    MEDIUM
    CVE-2022-47417

    LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document file name.... Read more

    Affected Products : logicaldoc
    • Published: Feb. 07, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-47424

    Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1.... Read more

    Affected Products :
    • Published: Nov. 19, 2024
    • Modified: Nov. 19, 2024
  • 5.4

    MEDIUM
    CVE-2022-46805

    Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets.... Read more

    • Published: Mar. 01, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-6796

    PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.... Read more

    • Published: Feb. 07, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-47053

    An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.... Read more

    Affected Products : dotnetnuke
    • Published: Apr. 12, 2023
    • Modified: Feb. 10, 2025
  • 5.4

    MEDIUM
    CVE-2022-46686

    Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitabl... Read more

    Affected Products : custom_build_properties
    • Published: Dec. 12, 2022
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-46503

    A cross-site scripting (XSS) vulnerability in the component /admin/register.php of Online Student Enrollment System v1.0 allows attackers to execute arbitrary web scripts via a crafted payload injected into the name parameter.... Read more

    Affected Products : online_student_enrollment_system
    • Published: Jan. 12, 2023
    • Modified: Apr. 08, 2025
Showing 20 of 294335 Results