Latest CVE Feed
-
5.4
MEDIUMCVE-2013-2895
drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or... Read more
Affected Products : linux_kernel- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2019-10432
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.... Read more
Affected Products : html_publisher- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8650
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft Sha... Read more
- Published: Dec. 12, 2018
- Modified: Feb. 28, 2025
-
5.4
MEDIUMCVE-2013-2688
Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP po... Read more
- Published: Jul. 12, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2024-24062
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.... Read more
Affected Products : springboot-manager- Published: Feb. 01, 2024
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2024-23941
Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the prod... Read more
Affected Products : group_office- Published: Feb. 01, 2024
- Modified: Jun. 04, 2025
-
5.4
MEDIUMCVE-2024-23905
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : red_hat_dependency_analytics- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2020-26063
A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper ... Read more
Affected Products : unified_computing_system- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
5.4
MEDIUMCVE-2020-0923
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from... Read more
- Published: Apr. 15, 2020
- Modified: Feb. 28, 2025
-
5.4
MEDIUMCVE-2020-26067
A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulne... Read more
Affected Products : webex_teams- Published: Nov. 18, 2024
- Modified: Aug. 01, 2025
-
5.4
MEDIUMCVE-2020-26046
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.... Read more
Affected Products : fuel_cms- Published: Jan. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25955
SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.... Read more
Affected Products : student_management_system_project_in_php- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25876
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Page Title' parameter.... Read more
Affected Products : codoforum- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25879
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Username' parameter.... Read more
Affected Products : codoforum- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-29497
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code under the device ta... Read more
Affected Products : wyse_management_suite- Published: Jan. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-26035
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.... Read more
Affected Products : zammad- Published: Dec. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-23782
Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.... Read more
Affected Products : a-blog_cms- Published: Jan. 28, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2013-1932
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.... Read more
Affected Products : mantisbt- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024