Latest CVE Feed
-
5.4
MEDIUMCVE-2017-10073
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily e... Read more
Affected Products : flexcube_universal_banking- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-10027
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage & Navigation). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows low privileged atta... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2020-3975
VMware App Volumes 2.x prior to 2.18.6 and VMware App Volumes 4 prior to 2006 contain a Stored Cross-Site Scripting (XSS) vulnerability. A malicious actor with access to create and edit applications or create storage groups, may be able to inject maliciou... Read more
Affected Products : app_volumes- Published: Aug. 21, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-10046
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable vulnerability all... Read more
Affected Products : primavera_p6_enterprise_project_portfolio_management- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1002011
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript in... Read more
Affected Products : image-gallery-with-slideshow- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000510
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.... Read more
Affected Products : croogo- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000462
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.... Read more
Affected Products : bookstack- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000442
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace... Read more
Affected Products : passbolt_api- Published: Jan. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000240
The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HT... Read more
Affected Products : openemr- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2020-2223
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.... Read more
Affected Products : jenkins- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-41955
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.... Read more
Affected Products : mobile_security_framework- Published: Jul. 31, 2024
- Modified: Aug. 15, 2024
-
5.4
MEDIUMCVE-2017-1000223
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control... Read more
Affected Products : modx_revolution- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2020-2190
Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.... Read more
Affected Products : script_security- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000239
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.... Read more
Affected Products : invoiceplane- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2020-2231
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permis... Read more
Affected Products : jenkins- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-1722
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unrespon... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000164
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation... Read more
Affected Products : tine_2.0- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-41875
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 27, 2024
-
5.4
MEDIUMCVE-2017-1000146
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script th... Read more
Affected Products : mahara- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-41911
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.... Read more
- Published: Aug. 06, 2024
- Modified: Oct. 28, 2024