Latest CVE Feed
-
5.4
MEDIUMCVE-2020-1063
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.... Read more
Affected Products : dynamics_365- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-0930
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from... Read more
- Published: Apr. 15, 2020
- Modified: Feb. 28, 2025
-
5.4
MEDIUMCVE-2020-10135
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent... Read more
- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30034
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.... Read more
Affected Products : remote_clinic- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3964
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter.... Read more
Affected Products : network_security_manager- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3933
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.... Read more
Affected Products : network_data_loss_prevention- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2019-7621
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kiban... Read more
Affected Products : kibana- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3961
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attribut... Read more
Affected Products : network_security_manager- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3902
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.... Read more
Affected Products : epolicy_orchestrator- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2019-6591
On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.... Read more
Affected Products : big-ip_access_policy_manager- Published: Feb. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3874
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2)... Read more
Affected Products : unified_communications_manager- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2019-20934
An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.... Read more
Affected Products : linux_kernel- Published: Nov. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-2460
Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account p... Read more
Affected Products : application_express- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-46494
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.... Read more
Affected Products : typecho- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-46409
A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.... Read more
Affected Products : seeddms- Published: Oct. 04, 2024
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2024-46209
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.... Read more
Affected Products : redaxo- Published: Jan. 06, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-46081
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to v... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46083
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is importa... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-45986
A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and p... Read more
- Published: Sep. 26, 2024
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2017-3482
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily "exploita... Read more
Affected Products : flexcube_universal_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025