Latest CVE Feed
-
5.4
MEDIUMCVE-2018-1000218
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script o... Read more
Affected Products : openemr- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000219
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script o... Read more
Affected Products : openemr- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24168
The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. Thi... Read more
Affected Products : easy_contact_form_pro- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24187
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.... Read more
Affected Products : seo_redirection- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24153
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.... Read more
Affected Products : yoast_seo- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000084
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to ... Read more
Affected Products : wolf_cms- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-26643
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.... Read more
Affected Products : edge_chromium- Published: Mar. 07, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-22220
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin use... Read more
- Published: Jan. 30, 2025
- Modified: May. 14, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2021-29713
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ... Read more
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0698
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : growi- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0577
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wp_google_map- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0618
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 26, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0551
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-8186
An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.... Read more
Affected Products : gitlab- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2018-0585
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : ultimate_member- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0549
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0482
A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The... Read more
Affected Products : prime_infrastructure- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0408
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based manage... Read more
Affected Products : sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware sf300-24mp_firmware +46 more products- Published: Aug. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-56355
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS... Read more
Affected Products : teamcity- Published: Dec. 20, 2024
- Modified: Jan. 02, 2025
-
5.4
MEDIUMCVE-2018-0367
A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affecte... Read more
Affected Products : registered_envelope_service- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024