Export limit exceeded: 351458 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46005 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-34831 | 1 Odysseycs | 1 Ithacalabs Turnitin Lti | 2024-11-27 | 5.4 Medium |
| The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security issue affects the submission web form ("id" and "title" HTTP POST parameters) where the students submit their reports for similarity/plagiarism checks. | ||||
| CVE-2023-36484 | 1 Ilias | 1 Ilias | 2024-11-26 | 6.1 Medium |
| ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS). | ||||
| CVE-2023-33335 | 1 Sophos | 1 Iview | 2024-11-26 | 6.1 Medium |
| Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed. | ||||
| CVE-2023-42325 | 1 Netgate | 1 Pfsense | 2024-11-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page. | ||||
| CVE-2024-48415 | 2 Itsourcecode, Razormist | 2 Loan Management System, Loan Management System | 2024-11-26 | 4.6 Medium |
| itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page. | ||||
| CVE-2022-37139 | 1 Razormist | 1 Loan Management System | 2024-11-26 | 5.4 Medium |
| Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability. | ||||
| CVE-2023-37256 | 1 Mediawiki | 1 Mediawiki | 2024-11-26 | 6.1 Medium |
| An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs. | ||||
| CVE-2023-33276 | 1 Gira | 2 Knx Ip Router, Knx Ip Router Firmware | 2024-11-26 | 6.1 Medium |
| The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding, it is vulnerable to reflective cross-site scripting (XSS). | ||||
| CVE-2023-37251 | 1 Mediawiki | 1 Mediawiki | 2024-11-26 | 6.1 Medium |
| An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs. | ||||
| CVE-2023-37255 | 1 Mediawiki | 1 Mediawiki | 2024-11-26 | 6.1 Medium |
| An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header. | ||||
| CVE-2023-49215 | 1 Usedesk | 1 Usedesk | 2024-11-26 | 6.1 Medium |
| Usedesk before 1.7.57 allows filter reflected XSS. | ||||
| CVE-2023-48880 | 1 Eyoucms | 1 Eyoucms | 2024-11-26 | 4.8 Medium |
| A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu Name field at /login.php?m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn. | ||||
| CVE-2023-36471 | 1 Xwiki | 1 Commons | 2024-11-26 | 9.1 Critical |
| Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println("Hello from Groovy!")" />{{/html}}` that would allow remote code execution when it is submitted by an admin (the sheet is rendered as part of the edit form). The attacker would need to ensure that the edit form looks plausible, though, which can be non-trivial as without script right the attacker cannot display the regular content of the document. This has been patched in XWiki 14.10.6 and 15.2RC1 by removing the central form-related tags from the list of allowed tags. Users are advised to upgrade. As a workaround an admin can manually disallow the tags by adding `form, input, select, textarea, button` to the configuration option `xml.htmlElementSanitizer.forbidTags` in the `xwiki.properties` configuration file. | ||||
| CVE-2023-34486 | 1 Online Hotel Management System Project | 1 Online Hotel Management System | 2024-11-26 | 6.1 Medium |
| itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box. | ||||
| CVE-2023-49490 | 1 Xunruicms | 1 Xunruicms | 2024-11-26 | 6.1 Medium |
| XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php. | ||||
| CVE-2023-36647 | 1 Prolion | 1 Cryptospike | 2024-11-26 | 7.5 High |
| A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens. | ||||
| CVE-2023-34599 | 1 Gibbonedu | 1 Gibbon | 2024-11-26 | 6.1 Medium |
| Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code. | ||||
| CVE-2023-34648 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2024-11-26 | 6.1 Medium |
| A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | ||||
| CVE-2024-9768 | 1 Strategy11 | 1 Formidable Forms | 2024-11-26 | 4.8 Medium |
| The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-46499 | 1 Evershop | 1 Evershop | 2024-11-26 | 6.1 Medium |
| Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel. | ||||