Export limit exceeded: 376620 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376620 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48099 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-23022 | 1 Oretnom23 | 1 Employees Payroll Management System | 2025-03-26 | 6.1 Medium |
| Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows attackers to execute arbitrary code via the code, title, from_date and to_date inputs in file Main.php. | ||||
| CVE-2023-0608 | 1 Microweber | 1 Microweber | 2025-03-26 | 5.4 Medium |
| Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. | ||||
| CVE-2024-45625 | 1 Incsub | 1 Forminator | 2025-03-26 | 6.1 Medium |
| Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator. | ||||
| CVE-2024-39242 | 1 Skycaiji | 1 Skycaiji | 2025-03-26 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()). | ||||
| CVE-2024-25731 | 1 Elinksmart | 1 Esmartcam | 2025-03-26 | 7.5 High |
| The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi). | ||||
| CVE-2022-48113 | 1 Totolink | 2 N200re-v5, N200re-v5 Firmware | 2025-03-26 | 9.8 Critical |
| A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials. | ||||
| CVE-2022-48085 | 1 Softr | 1 Softr | 2025-03-26 | 5.4 Medium |
| Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. | ||||
| CVE-2023-24147 | 1 Totolink | 2 Ca300-poe, Ca300-poe Firmware | 2025-03-26 | 7.5 High |
| TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini. | ||||
| CVE-2023-23636 | 1 Jellyfin | 1 Jellyfin | 2025-03-26 | 5.4 Medium |
| In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim. | ||||
| CVE-2023-23635 | 1 Jellyfin | 1 Jellyfin | 2025-03-26 | 5.4 Medium |
| In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim. | ||||
| CVE-2022-48140 | 1 Dedecms | 1 Dedecms | 2025-03-26 | 5.4 Medium |
| DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.php?fmdo=edit&filename. | ||||
| CVE-2021-37518 | 1 Vimium Project | 1 Vimium | 2025-03-26 | 6.1 Medium |
| Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run arbitrary code via omnibar feature. | ||||
| CVE-2021-37502 | 1 Automad | 1 Automad | 2025-03-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user name field when adding a user. | ||||
| CVE-2021-37378 | 1 Teradke | 4 Cube, Cube Firmware, Cube Pro and 1 more | 2025-03-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue. | ||||
| CVE-2021-37373 | 1 Teradek | 2 Slice, Slice Firmware | 2025-03-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue. | ||||
| CVE-2022-47983 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2025-03-26 | 5.4 Medium |
| IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 243161. | ||||
| CVE-2025-2623 | 1 Westboy | 1 Cicadascms | 2025-03-26 | 3.5 Low |
| A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content/save. The manipulation of the argument title/content/laiyuan leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2021-36712 | 1 Yzmcms | 1 Yzmcms | 2025-03-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function. | ||||
| CVE-2021-36545 | 1 Tpcms Project | 1 Tpcms | 2025-03-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyright or cfg_tel field in Site Configuration page. | ||||
| CVE-2021-36538 | 1 Gurock | 1 Testrail | 2025-03-26 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports. | ||||