Total
28965 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-2430 | 1 Matteoenna | 1 Website Content In Page Or Post | 2024-08-01 | N/A | 5.4 MEDIUM |
The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |||||
CVE-2024-29278 | 2024-08-01 | N/A | 6.5 MEDIUM | ||
funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in "create a message ." | |||||
CVE-2024-28804 | 2024-08-01 | N/A | 7.1 HIGH | ||
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST. | |||||
CVE-2024-28725 | 2024-08-01 | N/A | 7.1 HIGH | ||
Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings. | |||||
CVE-2024-28676 | 2024-08-01 | N/A | 6.1 MEDIUM | ||
DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php. | |||||
CVE-2024-28671 | 2024-08-01 | N/A | 8.8 HIGH | ||
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php. | |||||
CVE-2024-28402 | 2024-08-01 | N/A | 5.9 MEDIUM | ||
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page. | |||||
CVE-2024-28157 | 2024-08-01 | N/A | 8.0 HIGH | ||
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs. | |||||
CVE-2024-27558 | 2024-08-01 | N/A | 6.1 MEDIUM | ||
Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings. | |||||
CVE-2024-27499 | 2024-08-01 | N/A | 6.5 MEDIUM | ||
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. | |||||
CVE-2024-25506 | 2024-08-01 | N/A | 6.5 MEDIUM | ||
Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie. | |||||
CVE-2024-25219 | 1 Task Manager In Php With Source Code Project | 1 Task Manager In Php With Source Code | 2024-08-01 | N/A | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Task Name parameter /TaskManager/Task.php. | |||||
CVE-2024-25208 | 1 Barangay Management System Project | 1 Barangay Management System | 2024-08-01 | N/A | 5.4 MEDIUM |
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter. | |||||
CVE-2024-23997 | 1 Lukasbach | 1 Yana | 2024-08-01 | N/A | 9.6 CRITICAL |
Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts. | |||||
CVE-2024-23995 | 2024-08-01 | N/A | 6.1 MEDIUM | ||
Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container. | |||||
CVE-2024-22444 | 1 Arubanetworks | 1 Edgeconnect Sd-wan Orchestrator | 2024-08-01 | N/A | 6.1 MEDIUM |
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface. | |||||
CVE-2024-1660 | 2024-08-01 | N/A | 4.8 MEDIUM | ||
The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2023-44855 | 2024-08-01 | N/A | 6.5 MEDIUM | ||
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted script to the rdiag, sender, and recipients parameters of the sub_219C4 function in the acu_web file. | |||||
CVE-2023-37539 | 1 Hcltech | 1 Domino | 2024-08-01 | N/A | 5.4 MEDIUM |
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it. | |||||
CVE-2020-27478 | 2024-08-01 | N/A | 7.1 HIGH | ||
Cross Site Scripting vulnerability found in Simplcommerce v.40734964b0811f3cbaf64b6dac261683d256f961 thru 3103357200c70b4767986544e01b19dbf11505a7 allows a remote attacker to execute arbitrary code via a crafted script to the search bar feature. |