Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-36662 | 1 Techtime | 1 User Management | 2024-11-21 | N/A | 5.4 MEDIUM |
|
The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.
|
|||||
| CVE-2023-36656 | 1 Jaegertracing | 1 Jaeger Ui | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component.
|
|||||
| CVE-2023-36637 | 1 Fortinet | 1 Fortimail | 2024-11-21 | N/A | 3.5 LOW |
|
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
|
|||||
| CVE-2023-36555 | 1 Fortinet | 1 Fortios | 2024-11-21 | N/A | 3.9 LOW |
|
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
|
|||||
| CVE-2023-36530 | 1 Smartypantsplugins | 1 Sp Project \& Document Manager | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
|
|||||
| CVE-2023-36503 | 1 Maxfoundry | 1 Maxbuttons | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Max Foundry WordPress Button Plugin MaxButtons plugin <= 9.5.3 versions.
|
|||||
| CVE-2023-36502 | 1 Cththemes | 1 Balkon | 2024-11-21 | N/A | 7.1 HIGH |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions.
|
|||||
| CVE-2023-36501 | 1 Mtrv | 1 Teachpress | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 9.0.2 versions.
|
|||||
| CVE-2023-36492 | 1 Ss-proj | 1 Shirasagi | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
|
|||||
| CVE-2023-36488 | 1 Ilias | 1 Ilias | 2024-11-21 | N/A | 5.4 MEDIUM |
|
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
|
|||||
| CVE-2023-36484 | 1 Ilias | 1 Ilias | 2024-11-21 | N/A | 6.1 MEDIUM |
|
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
|
|||||
| CVE-2023-36477 | 1 Xwiki | 2 Ckeditor Integration, Xwiki | 2024-11-21 | N/A | 9.0 CRITICAL |
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents, leading to loss of service and editing the javascript configuration of CKEditor, leading to persistent XSS. This issue has been patched in XWiki 14.10.6 and XWiki 15.1. This issue has been patched on the CKEditor Integratio ...
Show More |
|||||
| CVE-2023-36474 | 1 Projectdiscovery | 1 Interactsh | 2024-11-21 | N/A | 8.2 HIGH |
|
Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as default, which intended to used for hosting interactsh web client using GitHub pages. This is a security issue with a self-hosted interactsh server in which the user may not have config ...
Show More |
|||||
| CVE-2023-36473 | 1 Discourse | 1 Discourse | 2024-11-21 | N/A | 6.8 MEDIUM |
|
Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack to completely bypass CSP. The vulnerability is patched in the latest tests-passed, beta and stable branches.
|
|||||
| CVE-2023-36471 | 1 Xwiki | 1 Commons | 2024-11-21 | N/A | 9.0 CRITICAL |
|
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println("Hello from Groovy!")" />{{/html}}` that ...
Show More |
|||||
| CVE-2023-36463 | 1 Meldekarten Generator Project | 1 Meldekarten Generator | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after submission. This issue has been addressed in commit `77e04f4af` which is included in the `1.0.0b1.1.2` release. Users are advised to upgrade. There are no known workarounds for this vuln ...
Show More |
|||||
| CVE-2023-36459 | 1 Joinmastodon | 1 Mastodon | 2024-11-21 | N/A | 9.3 CRITICAL |
|
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. This introduces a vector for cross-site scripting (XSS) payloads that can be rendered in the user's browser when a preview card for a malicious link is clicked through. Versions 3.5.9, 4.0.5, and 4. ...
Show More |
|||||
| CVE-2023-36416 | 1 Microsoft | 1 Dynamics 365 | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
|||||
| CVE-2023-36410 | 1 Microsoft | 1 Dynamics 365 | 2024-11-21 | N/A | 7.6 HIGH |
|
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
|||||
| CVE-2023-36389 | 1 Siemens | 22 Ruggedcom Rox Mx5000, Ruggedcom Rox Mx5000 Firmware, Ruggedcom Rox Mx5000re and 19 more | 2024-11-21 | N/A | 8.8 HIGH |
|
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < ...
Show More |
|||||
| CVE-2023-36386 | 1 Siemens | 22 Ruggedcom Rox Mx5000, Ruggedcom Rox Mx5000 Firmware, Ruggedcom Rox Mx5000re and 19 more | 2024-11-21 | N/A | 8.8 HIGH |
|
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < ...
Show More |
|||||
| CVE-2023-36385 | 1 Wpxpo | 1 Postx | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpxpo PostX – Gutenberg Post Grid Blocks plugin <= 2.9.9 versions.
|
|||||
| CVE-2023-36384 | 1 Booking Calendar Project | 1 Booking Calendar | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
|
|||||
| CVE-2023-36383 | 1 Mage-people | 1 Event Manager And Tickets Selling For Woocommerce | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.
|
|||||
| CVE-2023-36382 | 1 Jeffrey-wp | 1 Media Library Categories | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeffrey-WP Media Library Categories plugin <= 2.0.0 versions.
|
|||||
| CVE-2023-36376 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
|
|||||
| CVE-2023-36346 | 1 Codekop | 1 Codekop | 2024-11-21 | N/A | 6.1 MEDIUM |
|
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.
|
|||||
| CVE-2023-36345 | 1 Codekop | 1 Codekop | 2024-11-21 | N/A | 8.8 HIGH |
|
A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.
|
|||||
| CVE-2023-36317 | 1 Oretnom23 | 1 Student Study Center Desk Management System | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.
|
|||||
| CVE-2023-36315 | 1 Phpjabbers | 1 Callback Widget | 2024-11-21 | N/A | 6.1 MEDIUM |
|
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0.
|
|||||
| CVE-2023-36314 | 1 Phpjabbers | 1 Callback Widget | 2024-11-21 | N/A | 6.1 MEDIUM |
|
There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.
|
|||||
| CVE-2023-36313 | 1 Phpjabbers | 1 Document Creator | 2024-11-21 | N/A | 6.1 MEDIUM |
|
PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".
|
|||||
| CVE-2023-36312 | 1 Phpjabbers | 1 Callback Widget | 2024-11-21 | N/A | 5.4 MEDIUM |
|
There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0.
|
|||||
| CVE-2023-36310 | 1 Phpjabbers | 1 Document Creator | 2024-11-21 | N/A | 6.1 MEDIUM |
|
There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
|
|||||
| CVE-2023-36309 | 1 Phpjabbers | 1 Document Creator | 2024-11-21 | N/A | 6.1 MEDIUM |
|
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.
|
|||||
| CVE-2023-36306 | 1 Adiscon | 1 Loganalyzer | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.
|
|||||
| CVE-2023-36291 | 1 Maxsite | 1 Maxsite Cms | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
|
|||||
| CVE-2023-36289 | 1 Webkul | 1 Qloapps | 2024-11-21 | N/A | 6.1 MEDIUM |
|
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
|
|||||
| CVE-2023-36288 | 1 Webkul | 1 Qloapps | 2024-11-21 | N/A | 5.4 MEDIUM |
|
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
|
|||||
| CVE-2023-36287 | 1 Webkul | 1 Qloapps | 2024-11-21 | N/A | 6.1 MEDIUM |
|
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
|
|||||