Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24156
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation... Read more
Affected Products : testimonial_rotator- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-12978
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.... Read more
Affected Products : cacti- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2713
HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370, versions earlier before VIE-L29C636B370 have an insufficient input validation vulnerability. An ... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2610
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with less-than and greater-than characters in their names (SECURITY-388).... Read more
Affected Products : jenkins- Published: May. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24147
Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author ... Read more
Affected Products : modern_events_calendar_lite- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-7469
A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +6 more products- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2255
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".... Read more
Affected Products : garoon- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3433
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web... Read more
Affected Products : business_intelligence- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2561
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database n... Read more
Affected Products : phpmyadmin- Published: Mar. 01, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-2127
Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : yop_poll- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2122
Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : nessus- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-20117
A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be lau... Read more
Affected Products : server- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20116
A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). I... Read more
Affected Products : server- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20056
A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to launch the attack remotely. The exp... Read more
Affected Products : user_login_log- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20061
A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to... Read more
Affected Products : elefant_cms- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20034
A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the file /lists/admin/ of the component List Name. The manipulation leads to cross site scripting (Persistent). The attack can be initiated re... Read more
Affected Products : phplist- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20044
A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to basic cross site scripting (Reflected). It is possible to initiate the attack remotely. Upgrading to ve... Read more
Affected Products : pricepoint- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24127
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24128
Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML... Read more
Affected Products : team_members- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24126
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege... Read more
Affected Products : envira_gallery- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024