Latest CVE Feed
-
5.4
MEDIUMCVE-2016-3652
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : endpoint_protection_manager- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-20769
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-20947
Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with n... Read more
Affected Products : common_applications- Published: Feb. 17, 2024
- Modified: Nov. 29, 2024
-
5.4
MEDIUMCVE-2024-11695
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 1... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2016-3509
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Folders / URL Attachment.... Read more
- Published: Jul. 21, 2016
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2016-3442
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Portal.... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-48621
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Sep. 19, 2025
-
5.4
MEDIUMCVE-2023-48586
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Sep. 19, 2025
-
5.4
MEDIUMCVE-2023-48581
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Sep. 19, 2025
-
5.4
MEDIUMCVE-2023-48545
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48508
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48499
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48485
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48462
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48461
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-3193
Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 and FortiAnalyzer 5.x before 5.0.13, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 allows remote ... Read more
- Published: Aug. 19, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3101
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.... Read more
Affected Products : extra_columns- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3054
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.... Read more
Affected Products : filenet_workplace- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3049
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force... Read more
Affected Products : openpages_grc_platform- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3031
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi... Read more
Affected Products : cognos_analytics- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025