Export limit exceeded: 45936 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (45936 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41614 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 4.8 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter. | ||||
| CVE-2023-41601 | 1 Cszcms | 1 Csz Cms | 2024-11-21 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters. | ||||
| CVE-2023-41597 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | 6.1 Medium |
| EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t. | ||||
| CVE-2023-41595 | 1 Vaxilu | 1 X-ui | 2024-11-21 | 7.5 High |
| An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. | ||||
| CVE-2023-41593 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2024-11-21 | 5.4 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters. | ||||
| CVE-2023-41592 | 1 Froala | 1 Froala Editor | 2024-11-21 | 5.4 Medium |
| Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability. | ||||
| CVE-2023-41588 | 1 Appfire | 1 Time To Sla | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Time to SLA plugin v10.13.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the durationFormat parameter. | ||||
| CVE-2023-41575 | 1 Phpgurukul | 1 Blood Bank \& Donor Management System | 2024-11-21 | 5.4 Medium |
| Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters. | ||||
| CVE-2023-41538 | 1 Phpjabbers | 1 Php Forum Script | 2024-11-21 | 6.1 Medium |
| phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | ||||
| CVE-2023-41508 | 1 Superstorefinder | 1 Super Store Finder | 2024-11-21 | 9.8 Critical |
| A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel. | ||||
| CVE-2023-41453 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component. | ||||
| CVE-2023-41451 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component. | ||||
| CVE-2023-41448 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component. | ||||
| CVE-2023-41447 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component. | ||||
| CVE-2023-41446 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component. | ||||
| CVE-2023-41445 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component. | ||||
| CVE-2023-41436 | 1 Cskaza | 1 Cszcms | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component. | ||||
| CVE-2023-41423 | 1 Terryl | 1 Wp Githuber Md | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in WP Githuber MD plugin v.1.16.2 allows a remote attacker to execute arbitrary code via a crafted payload to the new article function. | ||||
| CVE-2023-41372 | 1 Boschrexroth | 6 Ctrlx Hmi Web Panel Wr2107, Ctrlx Hmi Web Panel Wr2107 Firmware, Ctrlx Hmi Web Panel Wr2110 and 3 more | 2024-11-21 | 7.8 High |
| The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair | ||||
| CVE-2023-41343 | 1 Ragic | 1 Enterprise Cloud Database | 2024-11-21 | 5.4 Medium |
| Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack. | ||||