Latest CVE Feed
-
5.4
MEDIUMCVE-2021-46005
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.... Read more
Affected Products : car_rental_management_system- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45906
OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.... Read more
Affected Products : openwrt- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45787
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.... Read more
Affected Products : maccms- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45904
OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.... Read more
Affected Products : openwrt- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45744
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.... Read more
Affected Products : bludit- Published: Jan. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52857
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2021-45479
Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS.This issue affects Library Automation System: before 19.2. ... Read more
Affected Products : library_automation_system- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52858
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2024-52850
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2021-44970
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.... Read more
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52848
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2021-44855
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.... Read more
Affected Products : mediawiki- Published: Dec. 26, 2022
- Modified: Apr. 14, 2025
-
5.4
MEDIUMCVE-2021-45227
An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.... Read more
Affected Products : coins_construction_cloud- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44607
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.... Read more
Affected Products : fuel_cms- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44202
Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035... Read more
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44317
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.... Read more
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44120
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and ava... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44118
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into ... Read more
Affected Products : spip- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44091
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44043
An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their ow... Read more
Affected Products : app_studio- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024