Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-39515 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by administrative cacti accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_debug.php` displays data source related debugging information such as _data source paths, polling settings, meta-d ...
Show More |
|||||
| CVE-2023-39513 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `host.php` is used to monitor and manage hosts in the _cacti_ app, hence displays useful information such as d ...
Show More |
|||||
| CVE-2023-39512 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The script under `data_sources.php` displays the data source management information (e.g. data source path, polling configurati ...
Show More |
|||||
| CVE-2023-39510 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The`reports_admin.php` script displays reporting information about graphs, devices, data sources etc.
CENSUS found that an adversary ...
Show More |
|||||
| CVE-2023-39437 | 1 Sap | 1 Business One | 2024-11-21 | N/A | 7.6 HIGH |
|
SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to harmful action affecting the Confidentiality, Integrity and Availability of the application.
|
|||||
| CVE-2023-39429 | 1 Furunosystems | 24 Acera 1010, Acera 1010 Firmware, Acera 1020 and 21 more | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ...
Show More |
|||||
| CVE-2023-39370 | 1 Startrinity | 1 Softswitch | 2024-11-21 | N/A | 8.8 HIGH |
|
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
|
|||||
| CVE-2023-39369 | 1 Startrinity | 1 Softswitch | 2024-11-21 | N/A | 8.8 HIGH |
|
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
|
|||||
| CVE-2023-39366 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. The `data_sources.php` script displays the data source management information (e.g. data source path, polling configuration etc.) for ...
Show More |
|||||
| CVE-2023-39360 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cacti is an open source operational monitoring and fault management framework.Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data. The vulnerability is found in `graphs_new.php`. Several validations are performed, but the `returnto` parameter is directly passed to `form_save_button`. In order to bypass this validation, returnto must contain `host.php`. This vulnerability has been addressed in version 1.2.25. Users are adv ...
Show More |
|||||
| CVE-2023-39319 | 1 Golang | 1 Go | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.
|
|||||
| CVE-2023-39318 | 1 Golang | 1 Go | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.
|
|||||
| CVE-2023-39314 | 1 Te-st | 1 Leyka | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.30.2 versions.
|
|||||
| CVE-2023-39306 | 2024-11-21 | N/A | 7.1 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through 3.11.1.
|
|||||
| CVE-2023-39266 | 2 Arubanetworks, Hpe | 11 Aruba 2530, Aruba 2530ya, Aruba 2530yb and 8 more | 2024-11-21 | N/A | 8.3 HIGH |
|
A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
|
|||||
| CVE-2023-39208 | 1 Zoom | 1 Zoom | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.
|
|||||
| CVE-2023-39175 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | N/A | 4.6 MEDIUM |
|
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
|
|||||
| CVE-2023-39164 | 1 Amitzy | 1 Molongui | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions.
|
|||||
| CVE-2023-39162 | 1 Xlplugins | 1 Woo-confirmation-email | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.
|
|||||
| CVE-2023-39151 | 1 Jenkins | 1 Jenkins | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
|
|||||
| CVE-2023-39097 | 1 Webboss | 1 Webboss.io Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability.
|
|||||
| CVE-2023-39096 | 1 Webboss | 1 Webboss.io Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and output encoding.
|
|||||
| CVE-2023-39094 | 1 Zerowdd | 1 Studentmanager | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code via the username parameter in the student list function.
|
|||||
| CVE-2023-39067 | 1 Zlmediakit | 1 Zlmediakit | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL.
|
|||||
| CVE-2023-39062 | 1 Html2pdf Project | 1 Html2pdf | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.
|
|||||
| CVE-2023-39007 | 1 Opnsense | 1 Opnsense | 2024-11-21 | N/A | 9.6 CRITICAL |
|
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.
|
|||||
| CVE-2023-39006 | 1 Opnsense | 1 Opnsense | 2024-11-21 | N/A | 5.4 MEDIUM |
|
The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.
|
|||||
| CVE-2023-39002 | 1 Opnsense | 1 Opnsense | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-39000 | 1 Opnsense | 1 Opnsense | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.
|
|||||
| CVE-2023-38974 | 1 Uatech | 1 Badaso | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
|
|||||
| CVE-2023-38973 | 1 Uatech | 1 Badaso | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
|
|||||
| CVE-2023-38971 | 1 Uatech | 1 Badaso | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the rack number parameter in the add new rack function.
|
|||||
| CVE-2023-38970 | 1 Uatech | 1 Badaso | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.
|
|||||
| CVE-2023-38969 | 1 Uatech | 1 Badaso | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book function.
|
|||||
| CVE-2023-38964 | 1 Creativeitem | 1 Academy Lms | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
|
|||||
| CVE-2023-38911 | 1 Cszcms | 1 Csz Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.
|
|||||
| CVE-2023-38910 | 1 Cszcms | 1 Csz Cms | 2024-11-21 | N/A | 6.1 MEDIUM |
|
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.
|
|||||
| CVE-2023-38904 | 1 Decapcms | 1 Netlify Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.
|
|||||
| CVE-2023-38888 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-11-21 | N/A | 9.6 CRITICAL |
|
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
|
|||||
| CVE-2023-38883 | 1 Os4ed | 1 Opensis | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.
|
|||||