Latest CVE Feed
-
5.4
MEDIUMCVE-2017-8005
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Ident... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-25727
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.... Read more
Affected Products : phpmyadmin- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2017-7823
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched fr... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-7735
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.... Read more
Affected Products : fortios- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7514
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.... Read more
Affected Products : satellite- Published: Jul. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-7422
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to by... Read more
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-44473
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-7352
Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject arbitrary web script or HTML via the "host" parameter on the 'System > Configuration > SNMP > Add SNMP Trap Manager' screen.... Read more
Affected Products : purity- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7298
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.... Read more
Affected Products : moodle- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-39332
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3... Read more
- Published: Nov. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-7255
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-34184
Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by att... Read more
Affected Products : crx_content_package_deployer- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3066
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a pr... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
5.4
MEDIUMCVE-2024-49523
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Nov. 07, 2024
- Modified: Dec. 02, 2024
-
5.4
MEDIUMCVE-2017-6871
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, th... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6817
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.... Read more
- Published: Mar. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-49524
Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Nov. 07, 2024
- Modified: Dec. 02, 2024
-
5.4
MEDIUMCVE-2017-6749
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affe... Read more
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6715
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. Affected Products: Cisco Firepower Management Cente... Read more
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6764
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an... Read more
Affected Products : adaptive_security_appliance_software- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025