Search
Total
13741 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-48313 | 1 Umbraco | 1 Umbraco Cms | 2023-12-14 | N/A | 6.1 MEDIUM |
| Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scripting (XSS) vulnerability enabling attackers to bring malicious content into a website or application. Versions 10.8.1 and 12.3.4 contain a patch for this issue. | |||||
| CVE-2023-48642 | 1 Archerirm | 1 Archer | 2023-12-14 | N/A | 5.4 MEDIUM |
| Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release. | |||||
| CVE-2023-49563 | 1 Voltronicpower | 1 Snmp Web Pro | 2023-12-14 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver. | |||||
| CVE-2023-49802 | 1 Mantisbt | 1 Linked Custom Fields | 2023-12-14 | N/A | 6.1 MEDIUM |
| The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution. | |||||
| CVE-2023-48715 | 1 Enalean | 1 Tuleap | 2023-12-14 | N/A | 5.4 MEDIUM |
| Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.99.103 or Tuleap Community Edition and prior to versions 15.2-4 and 15.1-8 of Tuleap Enterprise Edition, the name of the releases are not properly escaped on the edition page of a release. A malicious user with the ability to create a FRS release could force a victim having write permissions in the FRS to execute uncontrolled code. Tuleap Community Edition 15.2.99.103, Tuleap Enterprise Edition 15.2-4, and Tuleap Enterprise Edition 15.1-8 contain a fix for this issue. | |||||
| CVE-2023-42476 | 1 Sap | 1 Businessobjects Web Intelligence | 2023-12-14 | N/A | 6.8 MEDIUM |
| SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to exposure of the data that the user has access to. In the worst case, attacker could access data from reporting databases. | |||||
| CVE-2023-49028 | 1 Absis | 1 Absis | 2023-12-13 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the user parameter in the lock/lock.php file. | |||||
| CVE-2023-50465 | 1 Monicahq | 1 Monica | 2023-12-13 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user. | |||||
| CVE-2023-5757 | 1 Themeum | 1 Wp Crowdfunding | 2023-12-13 | N/A | 4.8 MEDIUM |
| The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
| CVE-2023-5750 | 1 Wpdeveloper | 1 Embedpress | 2023-12-13 | N/A | 6.1 MEDIUM |
| The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
| CVE-2023-5749 | 1 Wpdeveloper | 1 Embedpress | 2023-12-13 | N/A | 6.1 MEDIUM |
| The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
| CVE-2023-45671 | 1 Frigate | 1 Frigate | 2023-12-13 | N/A | 4.7 MEDIUM |
| Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue. | |||||
| CVE-2023-49782 | 1 Collaboraoffice | 1 Richdocumentscode | 2023-12-13 | N/A | 6.1 MEDIUM |
| Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with `Collabora Online - Built-in CODE Server` app can be vulnerable to attack via proxy.php. The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.601. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-49490 | 1 Xunruicms | 1 Xunruicms | 2023-12-13 | N/A | 6.1 MEDIUM |
| XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php. | |||||
| CVE-2023-5940 | 1 Wpajans | 1 Wp Not Login Hide | 2023-12-13 | N/A | 4.8 MEDIUM |
| The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
| CVE-2023-5955 | 1 Codepeople | 1 Contact Form Email | 2023-12-13 | N/A | 4.8 MEDIUM |
| The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
| CVE-2023-49488 | 1 Openfiler | 1 Openfiler | 2023-12-13 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the nic parameter. | |||||
| CVE-2023-6646 | 1 Sissbruecker | 1 Linkding | 2023-12-13 | N/A | 5.4 MEDIUM |
| A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.23.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-247338 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product. | |||||
| CVE-2023-49494 | 1 Dedecms | 1 Dedecms | 2023-12-13 | N/A | 6.1 MEDIUM |
| DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php. | |||||
| CVE-2022-48614 | 1 Semantic-mediawiki | 1 Semantic Mediawiki | 2023-12-13 | N/A | 6.1 MEDIUM |
| Special:Ask in Semantic MediaWiki before 4.0.2 allows Reflected XSS. | |||||
| CVE-2023-6609 | 1 Oscommerce | 1 Oscommerce | 2023-12-13 | N/A | 6.1 MEDIUM |
| A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %27%22%3E%3Cimg%2Fsrc%3D1+onerror%3Dalert%28document.cookie%29%3E leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247245 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2023-38435 | 1 Apache | 1 Felix Health Check Webconsole Plugin | 2023-12-13 | N/A | 6.1 MEDIUM |
| An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher. | |||||
| CVE-2023-6649 | 1 Phpgurukul | 1 Teacher Subject Allocation Management System | 2023-12-13 | N/A | 6.1 MEDIUM |
| A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument searchdata with the input <script>alert(5)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-247342 is the identifier assigned to this vulnerability. | |||||
| CVE-2023-6650 | 1 Oretnom23 | 1 Simple Invoice Generator System | 2023-12-13 | N/A | 6.1 MEDIUM |
| A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issue affects some unknown processing of the file login.php. The manipulation of the argument cashier leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247343. | |||||
| CVE-2023-28873 | 1 Seafile | 1 Seafile | 2023-12-12 | N/A | 5.4 MEDIUM |
| An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor. | |||||
| CVE-2020-25835 | 1 Microfocus | 1 Arcsight Management Center | 2023-12-12 | N/A | 5.4 MEDIUM |
| A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS). | |||||
| CVE-2023-46499 | 1 Evershop | 1 Evershop | 2023-12-12 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel. | |||||
| CVE-2023-46494 | 1 Evershop | 1 Evershop | 2023-12-12 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid function in admin/productGrid/Grid.jsx. | |||||
| CVE-2023-46495 | 1 Evershop | 1 Evershop | 2023-12-12 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the sortBy parameter. | |||||
| CVE-2023-34439 | 1 Pleasanter | 1 Pleasanter | 2023-12-12 | N/A | 5.4 MEDIUM |
| Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser. | |||||
| CVE-2023-6333 | 1 Controlbyweb | 6 X-301-24i, X-301-24i Firmware, X-301-i and 3 more | 2023-12-12 | N/A | 5.4 MEDIUM |
| The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session. | |||||
| CVE-2023-42325 | 1 Netgate | 1 Pfsense | 2023-12-12 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page. | |||||
| CVE-2023-42327 | 1 Netgate | 1 Pfsense | 2023-12-12 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page. | |||||
| CVE-2023-6616 | 1 Oretnom23 | 1 Simple Student Attendance System | 2023-12-12 | N/A | 6.1 MEDIUM |
| A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247253 was assigned to this vulnerability. | |||||
| CVE-2023-6613 | 1 Typecho | 1 Typecho | 2023-12-12 | N/A | 4.8 MEDIUM |
| A vulnerability classified as problematic has been found in Typecho 1.2.1. Affected is an unknown function of the file /admin/options-theme.php of the component Logo Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247248. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2023-23372 | 1 Qnap | 2 Qts, Quts Hero | 2023-12-12 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h4.5.4.2476 build 20230728 and later | |||||
| CVE-2023-41171 | 1 Netscout | 1 Ngeniusone | 2023-12-12 | N/A | 5.4 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). | |||||
| CVE-2023-41170 | 1 Netscout | 1 Ngeniusone | 2023-12-12 | N/A | 6.1 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. | |||||
| CVE-2023-41169 | 1 Netscout | 1 Ngeniusone | 2023-12-12 | N/A | 5.4 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4). | |||||
| CVE-2023-41168 | 1 Netscout | 1 Ngeniusone | 2023-12-12 | N/A | 5.4 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4). | |||||
| CVE-2023-49493 | 1 Dedecms | 1 Dedecms | 2023-12-12 | N/A | 6.1 MEDIUM |
| DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php. | |||||
| CVE-2023-49492 | 1 Dedecms | 1 Dedecms | 2023-12-12 | N/A | 6.1 MEDIUM |
| DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php. | |||||
| CVE-2023-41172 | 1 Netscout | 1 Ngeniusone | 2023-12-12 | N/A | 5.4 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). | |||||
| CVE-2023-41905 | 1 Netscout | 1 Ngeniusone | 2023-12-12 | N/A | 5.4 MEDIUM |
| NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user. | |||||
| CVE-2023-6146 | 1 Qualys | 1 Private Cloud Platform | 2023-12-12 | N/A | 5.4 MEDIUM |
| A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. | |||||
| CVE-2023-49485 | 1 Jfinalcms Project | 1 Jfinalcms | 2023-12-12 | N/A | 5.4 MEDIUM |
| JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department. | |||||
| CVE-2023-49487 | 1 Jfinalcms Project | 1 Jfinalcms | 2023-12-12 | N/A | 5.4 MEDIUM |
| JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department. | |||||
| CVE-2023-49486 | 1 Jfinalcms Project | 1 Jfinalcms | 2023-12-12 | N/A | 5.4 MEDIUM |
| JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department. | |||||
| CVE-2023-43102 | 1 Zimbra | 1 Collaboration | 2023-12-12 | N/A | 6.1 MEDIUM |
| An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36. | |||||
| CVE-2023-43103 | 1 Zimbra | 1 Collaboration | 2023-12-12 | N/A | 6.1 MEDIUM |
| An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36. | |||||
