Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-27378 | 1 F5 | 19 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 16 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
|
|||||
| CVE-2023-27245 | 1 File Management System Project | 1 File Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Edit User module.
|
|||||
| CVE-2023-27241 | 1 Water Billing System Project | 1 Water Billing System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module.
|
|||||
| CVE-2023-27225 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.
|
|||||
| CVE-2023-27212 | 1 Online Pizza Ordering System Project | 1 Online Pizza Ordering System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
|
|||||
| CVE-2023-27211 | 1 Online Pizza Ordering System Project | 1 Online Pizza Ordering System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
|
|||||
| CVE-2023-27208 | 1 Online Pizza Ordering System Project | 1 Online Pizza Ordering System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
|
|||||
| CVE-2023-27206 | 1 Best Pos Management System Project | 1 Best Pos Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
|
|||||
| CVE-2023-27150 | 1 Opencrx | 1 Opencrx | 2024-11-21 | N/A | 5.4 MEDIUM |
|
openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.
|
|||||
| CVE-2023-27149 | 1 Enhancesoft | 1 Osticket | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.
|
|||||
| CVE-2023-27148 | 1 Enhancesoft | 1 Osticket | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.
|
|||||
| CVE-2023-27121 | 1 Pleasantsolutions | 1 Pleasant Password Server | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.
|
|||||
| CVE-2023-27082 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
|
|||||
| CVE-2023-26961 | 1 Alteryx | 1 Alteryx Server | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.
|
|||||
| CVE-2023-26958 | 1 Phpgurukul | 1 Park Ticketing Management System | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.
|
|||||
| CVE-2023-26955 | 1 Onekeyadmin Project | 1 Onekeyadmin | 2024-11-21 | N/A | 5.4 MEDIUM |
|
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.
|
|||||
| CVE-2023-26951 | 1 Onekeyadmin | 1 Onekeyadmin | 2024-11-21 | N/A | 5.4 MEDIUM |
|
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module.
|
|||||
| CVE-2023-26913 | 1 Evolucare | 1 Ecs Imaging | 2024-11-21 | N/A | 6.1 MEDIUM |
|
EVOLUCARE ECSIMAGING (aka ECS Imaging) < 6.21.5 is vulnerable to Cross Site Scripting (XSS) via new_movie. php.
|
|||||
| CVE-2023-26608 | 1 Vxcontrol | 1 Soldr | 2024-11-21 | N/A | 5.4 MEDIUM |
|
SOLDR (System of Orchestration, Lifecycle control, Detection and Response) 1.1.0 allows stored XSS via the module editor.
|
|||||
| CVE-2023-26577 | 1 Idattend | 1 Idweb | 2024-11-21 | N/A | 7.5 HIGH |
|
Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the browsing session of the logged in user.
|
|||||
| CVE-2023-26541 | 1 Asmember Project | 1 Asmember | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions.
|
|||||
| CVE-2023-26539 | 1 Advanced Text Widget Project | 1 Advanced Text Widget | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versions.
|
|||||
| CVE-2023-26538 | 1 Chat Bee Project | 1 Chat Bee | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamyabsoft Chat Bee plugin <= 1.1.0 versions.
|
|||||
| CVE-2023-26537 | 1 Wp No External Links Project | 1 Wp No External Links | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions.
|
|||||
| CVE-2023-26536 | 1 Followmedarling | 1 Spotify-play-button-for-wordpress | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.05 versions.
|
|||||
| CVE-2023-26534 | 1 Onewebsite | 1 Wp Repost | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions.
|
|||||
| CVE-2023-26530 | 1 Updraftplus | 1 Updraft | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.
|
|||||
| CVE-2023-26529 | 1 Dupeoff Project | 1 Dupeoff | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DupeOff.Com DupeOff plugin <= 1.6 versions.
|
|||||
| CVE-2023-26528 | 1 Shipyaari | 1 Shipping Management | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jinit9906 Shipyaari Shipping Management plugin <= 1.0 versions.
|
|||||
| CVE-2023-26527 | 1 Wpindeed | 1 Debug Assistant | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
|
|||||
| CVE-2023-26519 | 1 Publish To Schedule Project | 1 Publish To Schedule | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.5.4 versions.
|
|||||
| CVE-2023-26517 | 1 Plugin-planet | 1 Dashboard Widget Suite | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions.
|
|||||
| CVE-2023-26515 | 1 Simple Slug Translate Project | 1 Simple Slug Translate | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versions.
|
|||||
| CVE-2023-26491 | 1 Rsshub | 1 Rsshub | 2024-11-21 | N/A | 5.4 MEDIUM |
|
RSSHub is an open source and extensible RSS feed generator. When the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code. Users who access the deliberately constructed URL are affected. This vulnerability was fixed in version c910c4d28717fb860fbe064736641f379fab2c91. Please upgrade to this or a later version, there are no known workarounds.
|
|||||
| CVE-2023-26487 | 2 Vega-functions Project, Vega Project | 2 Vega-functions, Vega | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.`lassoAppend' function accepts 3 arguments and internally invokes `push` function on the 1st argument specifying array consisting of 2nd and 3rd arguments as `push` call argument. The type of the 1st argument is supposed to be an array, but it's not enforced. This makes it possible to specify any object with a `push` function as the 1st argument, `push` function can be set to ...
Show More |
|||||
| CVE-2023-26486 | 2 Vega-functions Project, Vega Project | 2 Vega-functions, Vega | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. The Vega `scale` expression function has the ability to call arbitrary functions with a single controlled argument. The scale expression function passes a user supplied argument group to getScale, which is then used as if it were an internal context. The context.scales[name].value is accessed from group and called as a function back in scale. This can be exploited to escape ...
Show More |
|||||
| CVE-2023-26480 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 8.9 HIGH |
|
XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.
|
|||||
| CVE-2023-26465 | 1 Pega | 1 Pega Platform | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
|
|||||
| CVE-2023-26457 | 1 Sap | 1 Content Server | 2024-11-21 | N/A | 6.1 MEDIUM |
|
SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can read and modify some sensitive information but cannot delete the data.
|
|||||
| CVE-2023-26456 | 1 Open-xchange | 1 Ox Guard | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing an attacker to build a foothold. Sanitization is in place for product names now. No publicly available exploits are known.
|
|||||