Latest CVE Feed
-
5.4
MEDIUMCVE-2024-43721
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
5.4
MEDIUMCVE-2024-43722
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
5.4
MEDIUMCVE-2024-43720
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
5.4
MEDIUMCVE-2024-43713
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
5.4
MEDIUMCVE-2024-43744
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
5.4
MEDIUMCVE-2024-43715
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 17, 2024
-
5.4
MEDIUMCVE-2017-11775
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how Sha... Read more
Affected Products : sharepoint_enterprise_server- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-43445
A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different ... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2024-43412
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Use... Read more
Affected Products : xibo- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
5.4
MEDIUMCVE-2024-43396
Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitize... Read more
Affected Products : khoj- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
5.4
MEDIUMCVE-2017-11181
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.... Read more
Affected Products : rise_ultimate_project_manager- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-3816
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.... Read more
Affected Products : cacti- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-11127
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11201
application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.... Read more
Affected Products : finecms- Published: Jul. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-43006
A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a specially crafted POST request to /user/ask_edit.php?action=add, which includes malicious Ja... Read more
- Published: Aug. 16, 2024
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2024-42898
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.... Read more
Affected Products : nagios_xi- Published: Jan. 09, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-42766
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.... Read more
Affected Products : bus_ticket_reservation_system- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2017-10886
Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecif... Read more
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-42406
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channel... Read more
- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-42373
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants... Read more
Affected Products : student_life_cycle_management- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024