Latest CVE Feed
-
5.4
MEDIUMCVE-2016-2986
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.... Read more
- Published: Nov. 25, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2973
IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-2926
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 be... Read more
- Published: Nov. 25, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-31163
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to injec... Read more
Affected Products : sel-2241_rtac_module_firmware sel-3350_firmware sel-3505_firmware sel-3505-3_firmware sel-3530_firmware sel-3530-4_firmware sel-3532_firmware sel-3555_firmware sel-3560e_firmware sel-3560s_firmware +10 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-31156
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to injec... Read more
Affected Products : sel-2241_rtac_module_firmware sel-3350_firmware sel-3505_firmware sel-3505-3_firmware sel-3530_firmware sel-3530-4_firmware sel-3532_firmware sel-3555_firmware sel-3560e_firmware sel-3560s_firmware +10 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-2924
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the... Read more
Affected Products : biginsights- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-2888
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script o... Read more
Affected Products : jazz_reporting_service- Published: Jul. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2864
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7... Read more
- Published: Nov. 24, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-31155
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to injec... Read more
Affected Products : sel-2241_rtac_module_firmware sel-3350_firmware sel-3505_firmware sel-3505-3_firmware sel-3530_firmware sel-3530-4_firmware sel-3532_firmware sel-3555_firmware sel-3560e_firmware sel-3560s_firmware +10 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-2817
The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to cond... Read more
Affected Products : firefox- Published: Apr. 30, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2559
Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.... Read more
Affected Products : phpmyadmin- Published: Mar. 01, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2075
Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 16, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-42472
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.1... Read more
- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-2045
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.... Read more
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-3239
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributo... Read more
Affected Products : postx- Published: May. 14, 2024
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2024-3189
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' block... Read more
Affected Products : gutenberg_blocks_with_ai- Published: May. 15, 2024
- Modified: Feb. 07, 2025
-
5.4
MEDIUMCVE-2022-34172
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.... Read more
Affected Products : jenkins- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34170
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scrip... Read more
Affected Products : jenkins- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-30965
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Ite... Read more
Affected Products : promoted_builds- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3058
The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack... Read more
Affected Products : enl-newsletter- Published: Apr. 26, 2024
- Modified: May. 07, 2025