Latest CVE Feed
-
5.4
MEDIUMCVE-2020-2106
Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations.... Read more
Affected Products : code_coverage_api- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-16859
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a spec... Read more
Affected Products : dynamics_365- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-38217
Windows Mark of the Web Security Feature Bypass Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Actively Exploited
- Published: Sep. 10, 2024
- Modified: Jan. 27, 2025
-
5.4
MEDIUMCVE-2016-0925
Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and 7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authent... Read more
Affected Products : rsa_adaptive_authentication_on-premise- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-38036
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s b... Read more
Affected Products : portal_for_arcgis- Published: Oct. 04, 2024
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2016-0673
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to UIF Open UI.... Read more
Affected Products : siebel_ui_framework- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-37886
user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3... Read more
- Published: Jun. 14, 2024
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2024-37763
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-37396
A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to th... Read more
Affected Products : redcap- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-37394
A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. T... Read more
Affected Products : redcap- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2016-0387
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerabili... Read more
Affected Products : tririga_application_platform- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0316
Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : jazz_reporting_service- Published: Nov. 25, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0344
Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : tririga_application_platform- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0305
IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security c... Read more
Affected Products : connections- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-0285
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7... Read more
Affected Products : rational_team_concert- Published: Nov. 24, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0350
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script o... Read more
Affected Products : jazz_reporting_service- Published: Jul. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0331
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or... Read more
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0269
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : bigfix_platform- Published: Jul. 15, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0274
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (... Read more
Affected Products : financial_transaction_manager- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0253
Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before... Read more
Affected Products : financial_transaction_manager- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024