Latest CVE Feed
-
5.4
MEDIUMCVE-2020-7937
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.... Read more
Affected Products : plone- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7910
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.... Read more
Affected Products : teamcity- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7642
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.... Read more
Affected Products : lazysizes- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2005-3357
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NU... Read more
Affected Products : http_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2020-7676
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.... Read more
- Published: Jun. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7390
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Vers... Read more
- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7228
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.... Read more
Affected Products : calculated_fields_form- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7132
A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve t... Read more
Affected Products : onboard_administrator- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-5447
Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : storeonce_backup_system_software- Published: Jan. 05, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-5399
Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.... Read more
Affected Products : phpvibe- Published: Aug. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-11899
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.... Read more
- Actively Exploited
- Published: Jun. 17, 2020
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2015-5336
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the st... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-5269
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping descr... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-5181
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.... Read more
Affected Products : jboss_a-mq- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-5035
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability th... Read more
Affected Products : connections- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-48463
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48511
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48537
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-36174
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-41878
Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and execute arbitrary JavaScript code within the context of the user's browser ... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 27, 2024