Latest CVE Feed
-
5.4
MEDIUMCVE-2017-14587
The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-40143
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter. ... Read more
- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-14536
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.... Read more
Affected Products : trixbox- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-14359
A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.... Read more
Affected Products : performance_center- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14321
Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket.... Read more
Affected Products : helpdesk_mx- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-31160
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to injec... Read more
Affected Products : sel-2241_rtac_module_firmware sel-3350_firmware sel-3505_firmware sel-3505-3_firmware sel-3530_firmware sel-3530-4_firmware sel-3532_firmware sel-3555_firmware sel-3560e_firmware sel-3560s_firmware +10 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-31158
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to injec... Read more
Affected Products : sel-2241_rtac_module_firmware sel-3350_firmware sel-3505_firmware sel-3505-3_firmware sel-3530_firmware sel-3530-4_firmware sel-3532_firmware sel-3555_firmware sel-3560e_firmware sel-3560s_firmware +10 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-29454
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application uninte... Read more
- Published: Jul. 13, 2023
- Modified: Feb. 13, 2025
-
5.4
MEDIUMCVE-2017-13754
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attackers to inject arbitrary web script or HTML via the "server name" field in actions/ChangeConfiguration.html.... Read more
Affected Products : codemeter- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-13724
On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the "Basic Settings" page.... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-0119
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's sessi... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-12882
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.... Read more
Affected Products : spring_batch_admin- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-43420
Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to contr... Read more
Affected Products : contrast_continuous_application_security- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2017-12630
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query ... Read more
Affected Products : drill- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-42354
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-41225
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore ... Read more
Affected Products : anchore_container_image_scanner- Published: Sep. 21, 2022
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2017-12357
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected ... Read more
Affected Products : unified_communications_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12544
A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-12460
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a w... Read more
Affected Products : clickshare_csm-1_firmware clickshare_csc-1_firmware clickshare_csc-1 clickshare_csm-1- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12269
A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web UI of the affected so... Read more
Affected Products : spark- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025