Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-3035 | 1 Gougucms | 1 Pythagorean Oa Office System | 2024-11-21 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230467.
|
|||||
| CVE-2023-3034 | 1 Bund | 1 Bkg Professional Ntripcaster | 2024-11-21 | N/A | 4.7 MEDIUM |
|
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
|
|||||
| CVE-2023-3020 | 1 Scilicot | 1 I\, Librarian | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.
|
|||||
| CVE-2023-3016 | 1 Vip Video Analysis Project | 1 Vip Video Analysis | 2024-11-21 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in yiwent Vip Video Analysis 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/admincore.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230360.
|
|||||
| CVE-2023-3014 | 1 Beipyvideoresolution Project | 1 Beipyvideoresolution | 2024-11-21 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability, which was classified as problematic, was found in BeipyVideoResolution up to 2.6. Affected is an unknown function of the file admin/admincore.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230358 is the identifier assigned to this vulnerability.
|
|||||
| CVE-2023-3009 | 1 Teampass | 1 Teampass | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
|
|||||
| CVE-2023-3005 | 1 Local Service Search Engine Management System Project | 1 Local Service Search Engine Management System | 2024-11-21 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB ...
Show More |
|||||
| CVE-2023-39991 | 1 Blindsidenetworks | 1 Bigbluebutton | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions.
|
|||||
| CVE-2023-39988 | 1 Tencent | 1 Wxsync | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 标准云(std.Cloud) WxSync plugin <= 2.7.23 versions.
|
|||||
| CVE-2023-39987 | 1 Joomlaserviceprovider | 1 Wsecure | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions.
|
|||||
| CVE-2023-39971 | 1 Acymailing | 1 Acymailing | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.
|
|||||
| CVE-2023-39955 | 1 Nextcloud | 1 Notes | 2024-11-21 | N/A | 3.5 LOW |
|
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
|
|||||
| CVE-2023-39938 | 1 I-pro | 1 Video Insight | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to inject an arbitrary script.
|
|||||
| CVE-2023-39926 | 1 Acurax | 1 Under Construction \/ Maintenance Mode | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Acurax Under Construction / Maintenance Mode from Acurax plugin <= 2.6 versions.
|
|||||
| CVE-2023-39924 | 1 Simplefilelist | 1 Simple File List | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mitchell Bennis Simple File List plugin <= 6.1.9 versions.
|
|||||
| CVE-2023-39921 | 1 Amitzy | 1 Molongui | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui Author Box, Guest Author and Co-Authors for Your Posts – Molongui allows Stored XSS.This issue affects Author Box, Guest Author and Co-Authors for Your Posts – Molongui: from n/a through 4.6.19.
|
|||||
| CVE-2023-39919 | 1 Maennchen1 | 1 Wpshopgermany - Protected Shops | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany – Protected Shops plugin <= 2.0 versions.
|
|||||
| CVE-2023-39918 | 1 Saasproject | 1 Booking Package | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions.
|
|||||
| CVE-2023-39777 | 1 Vbulletin | 1 Vbulletin | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.
|
|||||
| CVE-2023-39714 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.
|
|||||
| CVE-2023-39712 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.
|
|||||
| CVE-2023-39711 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
|
|||||
| CVE-2023-39710 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.
|
|||||
| CVE-2023-39709 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.
|
|||||
| CVE-2023-39708 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.
|
|||||
| CVE-2023-39707 | 1 Free And Open Source Inventory Management System Project | 1 Free And Open Source Inventory Management System | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.
|
|||||
| CVE-2023-39703 | 1 Typora | 1 Typora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.
|
|||||
| CVE-2023-39700 | 1 Icewarp | 1 Mail Server | 2024-11-21 | N/A | 6.1 MEDIUM |
|
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
|
|||||
| CVE-2023-39678 | 1 Bdcom | 2 P3310d-2ac, P3310d-2ac Firmware | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
|
|||||
| CVE-2023-39676 | 1 Fieldthemes | 1 Fieldpopupnewsletter | 2024-11-21 | N/A | 6.1 MEDIUM |
|
FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.
|
|||||
| CVE-2023-39600 | 1 Icewarp | 1 Icewarp | 2024-11-21 | N/A | 6.1 MEDIUM |
|
IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
|
|||||
| CVE-2023-39598 | 1 Icewarp | 1 Webclient | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
|
|||||
| CVE-2023-39578 | 1 Tribalsystems | 1 Zenario | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.
|
|||||
| CVE-2023-39575 | 1 Isl | 1 Arp-guard | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-39558 | 1 Web-audimex | 1 Audimexee | 2024-11-21 | N/A | 6.1 MEDIUM |
|
AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component.
|
|||||
| CVE-2023-39543 | 1 Luxsoft | 1 Luxcal Web Calendar | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.
|
|||||
| CVE-2023-39527 | 1 Prestashop | 1 Prestashop | 2024-11-21 | N/A | 8.3 HIGH |
|
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
|
|||||
| CVE-2023-39521 | 1 Enalean | 1 Tuleap | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, content displayed in the "card fields" (visible in the kanban and PV2 apps) is not properly escaped. An agile dashboard administrator deleting a kanban with a malicious label can be forced to execute uncontrolled code. Tuleap Community Edition 14.11.99.28, Tuleap Enterprise Ed ...
Show More |
|||||
| CVE-2023-39518 | 1 Fobybus | 1 Social-media-skeleton | 2024-11-21 | N/A | 5.4 MEDIUM |
|
social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3.
|
|||||
| CVE-2023-39517 | 1 Joplin Project | 1 Joplin | 2024-11-21 | N/A | 8.2 HIGH |
|
Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`) preserves `<map>` `<area>` links. However, unlike `<a>` links, the `target` and `href` attributes are not removed. Additionally, because the note preview pane isn't sandboxed to prevent top navigation, links with `target` s ...
Show More |
|||||