Latest CVE Feed
-
5.4
MEDIUMCVE-2021-38928
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only... Read more
Affected Products : sterling_b2b_integrator- Published: Jan. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38903
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be execu... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-56352
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page... Read more
Affected Products : teamcity- Published: Dec. 20, 2024
- Modified: Jan. 02, 2025
-
5.4
MEDIUMCVE-2021-38707
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. Thi... Read more
Affected Products : cliniccases- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38681
A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from... Read more
- Published: Nov. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52862
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2024-52859
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2021-38675
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of ... Read more
- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52823
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
5.4
MEDIUM- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38269
Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web sc... Read more
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38221
bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.... Read more
Affected Products : bbs-go- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-41877
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 27, 2024
-
5.4
MEDIUMCVE-2024-41732
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web ap... Read more
Affected Products : netweaver_application_server_abap- Published: Aug. 13, 2024
- Modified: Sep. 11, 2024
-
5.4
MEDIUMCVE-2021-38152
index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.... Read more
Affected Products : patient_management_system- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-39926
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attack... Read more
Affected Products : vaultwarden- Published: Sep. 13, 2024
- Modified: Jul. 10, 2025
-
5.4
MEDIUMCVE-2024-36371
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible... Read more
Affected Products : teamcity- Published: May. 29, 2024
- Modified: Feb. 07, 2025
-
5.4
MEDIUMCVE-2024-36203
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37805
A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.... Read more
Affected Products : vehicle_parking_management_system- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37704
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation... Read more
Affected Products : phpfastcache- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024