Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-37135 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-37134 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-37133 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-37132 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-37125 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-37124 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2023-37122 | 1 Bagesoft | 1 Bagecms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.
|
|||||
| CVE-2023-37070 | 1 Code-projects | 1 Hospital Information System | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
|
|||||
| CVE-2023-37067 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
|
|||||
| CVE-2023-37066 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
|
|||||
| CVE-2023-37065 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
|
|||||
| CVE-2023-37064 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
|
|||||
| CVE-2023-37063 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
|
|||||
| CVE-2023-37062 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
|
|||||
| CVE-2023-37061 | 1 Chamilo | 1 Chamilo | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
|
|||||
| CVE-2023-36995 | 1 Travianz Project | 1 Travianz | 2024-11-21 | N/A | 6.1 MEDIUM |
|
TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.
|
|||||
| CVE-2023-36970 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
|
|||||
| CVE-2023-36942 | 1 Phpgurukul | 1 Online Fire Reporting System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.
|
|||||
| CVE-2023-36941 | 1 Phpgurukul | 1 Online Fire Reporting System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.
|
|||||
| CVE-2023-36940 | 1 Phpgurukul | 1 Online Fire Reporting System | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.
|
|||||
| CVE-2023-36939 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
|
|||||
| CVE-2023-36936 | 1 Phpgurukul | 1 Online Security Guards Hiring System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.
|
|||||
| CVE-2023-36918 | 1 Sap | 1 Enable Now | 2024-11-21 | N/A | 6.1 MEDIUM |
|
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information.
|
|||||
| CVE-2023-36892 | 1 Microsoft | 1 Sharepoint Server | 2024-11-21 | N/A | 8.0 HIGH |
|
Microsoft SharePoint Server Spoofing Vulnerability
|
|||||
| CVE-2023-36891 | 1 Microsoft | 1 Sharepoint Server | 2024-11-21 | N/A | 8.0 HIGH |
|
Microsoft SharePoint Server Spoofing Vulnerability
|
|||||
| CVE-2023-36886 | 1 Microsoft | 1 Dynamics 365 | 2024-11-21 | N/A | 7.6 HIGH |
|
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
|||||
| CVE-2023-36869 | 1 Microsoft | 1 Azure Devops Server | 2024-11-21 | N/A | 6.3 MEDIUM |
|
Azure DevOps Server Spoofing Vulnerability
|
|||||
| CVE-2023-36828 | 1 Statamic | 1 Statamic | 2024-11-21 | N/A | 5.5 MEDIUM |
|
Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue.
|
|||||
| CVE-2023-36823 | 2 Debian, Sanitize Project | 2 Debian Linux, Sanitize | 2024-11-21 | N/A | 7.1 HIGH |
|
Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. San ...
Show More |
|||||
| CVE-2023-36816 | 1 2fauth | 1 2fauth | 2024-11-21 | N/A | 6.1 MEDIUM |
|
2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested in docker-compose environment. This vulnerability has been patched in version 4.0.3.
|
|||||
| CVE-2023-36809 | 1 Kiwitcms | 1 Kiwi Tcms | 2024-11-21 | N/A | 8.1 HIGH |
|
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such files are accessed directly. The previous Nginx configuration was incorrect allowing certain browsers like Firefox to ignore the `Content-Type: text/plain` header on some occasions thu ...
Show More |
|||||
| CVE-2023-36806 | 1 Contao | 1 Contao | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4. ...
Show More |
|||||
| CVE-2023-36800 | 1 Microsoft | 1 Dynamics 365 | 2024-11-21 | N/A | 7.6 HIGH |
|
Dynamics Finance and Operations Cross-site Scripting Vulnerability
|
|||||
| CVE-2023-36692 | 1 Wp-cirrus Project | 1 Wp-cirrus | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Kramer & Hendrik Thole WP-Cirrus plugin <= 0.6.11 versions.
|
|||||
| CVE-2023-36689 | 1 Wpfactory | 1 Wpfactory Helper | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions.
|
|||||
| CVE-2023-36688 | 1 Idoweb | 1 Simple Site Verify | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.
|
|||||
| CVE-2023-36686 | 1 Cartflows | 1 Cartflows | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions.
|
|||||
| CVE-2023-36678 | 1 Wp-buy | 1 Wp Content Copy Protection \& No Right Click | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-buy WP Content Copy Protection & No Right Click plugin <= 3.5.5 versions.
|
|||||
| CVE-2023-36675 | 1 Mediawiki | 1 Mediawiki | 2024-11-21 | N/A | 6.1 MEDIUM |
|
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
|
|||||
| CVE-2023-36666 | 1 Inex | 1 Ixp Manager | 2024-11-21 | N/A | 6.1 MEDIUM |
|
INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, page-header-preamble.foil.php, overview.foil.php, cust.foil.php, and view.foil.php may be affected.
|
|||||