Latest CVE Feed
-
5.4
MEDIUMCVE-2021-30637
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.... Read more
Affected Products : htmly- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-2607
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs, adding new content or changing the presentation of existing content while ... Read more
Affected Products : jenkins- Published: May. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-17094
wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.... Read more
- Published: Dec. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14379
EMC RSA Authentication Manager before 8.2 SP1 P6 has a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : rsa_authentication_manager- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14370
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affecte... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11820
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how Sha... Read more
Affected Products : sharepoint_enterprise_server- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-30214
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.... Read more
Affected Products : knowage- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30146
Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."... Read more
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30111
A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visitor sees the events, then the payload will be executed.... Read more
Affected Products : enterprise_resource_planning- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-2373
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.5.3 and Prior. Easily exploitable vulnerability allows low privileged attacker with network access via ... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-0099
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-0097
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-2116
Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account pri... Read more
- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29872
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could ... Read more
Affected Products : cloud_pak_for_automation- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-6519
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-49796
IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch f... Read more
Affected Products : applinx- Published: Feb. 06, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2021-29818
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29677
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede... Read more
Affected Products : security_verify- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-4428
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.... Read more
- Published: Jul. 12, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-4399
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).... Read more
Affected Products : network_node_manager_i- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024