Export limit exceeded: 46126 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46126 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-2610 | 2 Mozilla, Redhat | 7 Firefox, Thunderbird, Enterprise Linux and 4 more | 2025-04-01 | 6.1 Medium |
| Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. | ||||
| CVE-2024-29473 | 1 Zhyd | 1 Oneblog | 2025-04-01 | 6.1 Medium |
| OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module. | ||||
| CVE-2024-10566 | 1 10web | 1 Slider | 2025-04-01 | 6.1 Medium |
| The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-13122 | 1 Advancedformintegration | 1 Advanced Form Integration | 2025-04-01 | 3.5 Low |
| The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-13123 | 1 Advancedformintegration | 1 Advanced Form Integration | 2025-04-01 | 3.5 Low |
| The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2022-47073 | 1 Small Crm Project | 1 Small Crm | 2025-04-01 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter. | ||||
| CVE-2022-46957 | 1 Online Graduate Tracer System Project | 1 Online Graduate Tracer System | 2025-04-01 | 6.1 Medium |
| Sourcecodester.com Online Graduate Tracer System V 1.0.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2022-46624 | 1 Online Graduate Tracer System Project | 1 Online Graduate Tracer System | 2025-04-01 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Online Graduate Tracer System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | ||||
| CVE-2022-45730 | 1 Phpgurukul | 1 Doctor Appointment Management System | 2025-04-01 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function. | ||||
| CVE-2024-1487 | 1 Contest-gallery | 1 Contest Gallery | 2025-04-01 | 5.4 Medium |
| The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks. | ||||
| CVE-2024-0559 | 2 Inisev, Themecheck | 2 Enhanced Text Widget, Enhanced Text Widget | 2025-04-01 | 6.5 Medium |
| The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2024-25868 | 1 Codeastro | 1 Membership Management System | 2025-04-01 | 6.1 Medium |
| A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component. | ||||
| CVE-2024-27083 | 1 Dpgaspar | 1 Flask-appbuilder | 2025-04-01 | 4.3 Medium |
| Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1. | ||||
| CVE-2024-27092 | 1 Hoppscotch | 1 Hoppscotch | 2025-04-01 | 5.4 Medium |
| Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easier to achieve own goals by malicious actors. This issue is fixed in 2023.12.6. | ||||
| CVE-2023-24494 | 1 Tenable | 1 Tenable.sc | 2025-04-01 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session. | ||||
| CVE-2022-46128 | 1 Phpgurukul | 1 Doctor Appointment Management System | 2025-04-01 | 6.1 Medium |
| phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=. | ||||
| CVE-2022-25847 | 1 Serve-lite Project | 1 Serve-lite | 2025-04-01 | 5.4 Medium |
| All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding. | ||||
| CVE-2020-22327 | 1 Hfish Project | 1 Hfish | 2025-04-01 | 6.1 Medium |
| An issue was discovered in HFish 0.5.1. When a payload is inserted where the name is entered, XSS code is triggered when the administrator views the information. | ||||
| CVE-2024-33371 | 1 Dedecms | 1 Dedecms | 2025-04-01 | 6.1 Medium |
| Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component. | ||||
| CVE-2024-33401 | 1 Dedecms | 1 Dedecms | 2025-04-01 | 4.4 Medium |
| Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter. | ||||