Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-33156 | 1 Matomo | 1 Integration | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
|
|||||
| CVE-2022-33155 | 1 Ameos Tarteaucitron Project | 1 Ameos Tarteaucitron | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS.
|
|||||
| CVE-2022-33154 | 1 Schema Project | 1 Schema | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.
|
|||||
| CVE-2022-33151 | 1 Cybozu | 1 Office | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors.
|
|||||
| CVE-2022-33122 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.
|
|||||
| CVE-2022-33119 | 1 Nuuo | 2 Nvrsolo, Nvrsolo Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
|
|||||
| CVE-2022-33113 | 1 Jflyfox | 1 Jfinal Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
|
|||||
| CVE-2022-33098 | 1 Magnolia-cms | 1 Magnolia Cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2022-33075 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.
|
|||||
| CVE-2022-33043 | 1 Urtracker | 1 Urtracker | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute arbitrary web scripts or HTML via a crafted excel file.
|
|||||
| CVE-2022-33009 | 1 Lightcms Project | 1 Lightcms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
|
|||||
| CVE-2022-33005 | 1 Deltaww | 1 Diaenergie | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.
|
|||||
| CVE-2022-32988 | 1 Asus | 2 Dsl-n14u-b1, Dsl-n14u-b1 Firmware | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc) in every ".asp" page containing a list of stored strings. The following asp files are affected: (1) cgi-bin/APP_Installation.asp, (2) cgi-bin/Advanced_ACL_Content.asp, (3) cgi-bin/Advanced_ADSL_Content.asp, (4) cgi-bin/Advanced_ASUSDDNS_Content.asp, (5) cgi-bin/Advanced_AiDisk_ftp.asp, (6) cgi-bin/Advanced_AiDisk_samba.asp, (7) cgi-bin/Advanced_DS ...
Show More |
|||||
| CVE-2022-32987 | 1 Simple Bakery Shop Management System Project | 1 Simple Bakery Shop Management System | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.
|
|||||
| CVE-2022-32970 | 1 Themify | 1 Portfolio Post | 2024-11-21 | N/A | 4.1 MEDIUM |
|
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versions.
|
|||||
| CVE-2022-32776 | 1 Wpadvancedads | 1 Advanced Ads - Ad Manager \& Adsense | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress.
|
|||||
| CVE-2022-32772 | 1 Wwbn | 1 Avideo | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "msg" parameter which is inserted into the document with insufficient sanitization.
|
|||||
| CVE-2022-32771 | 1 Wwbn | 1 Avideo | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.
|
|||||
| CVE-2022-32770 | 1 Wwbn | 1 Avideo | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "toast" parameter which is inserted into the document with insufficient sanitization.
|
|||||
| CVE-2022-32763 | 1 Lansweeper | 1 Lansweeper | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.
|
|||||
| CVE-2022-32754 | 1 Ibm | 1 Security Verify Directory | 2024-11-21 | N/A | 4.8 MEDIUM |
|
IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228445.
|
|||||
| CVE-2022-32750 | 1 Ibm | 1 Datapower Gateway | 2024-11-21 | N/A | 5.4 MEDIUM |
|
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228435.
|
|||||
| CVE-2022-32567 | 1 Appfire | 1 Jira Misc Custom Fields | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.
|
|||||
| CVE-2022-32533 | 1 Apache | 1 Jetspeed | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue
|
|||||
| CVE-2022-32442 | 1 Yuba | 1 U5cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the parameter passed in is http://127.0.0.1/? "Onmouseover=%27tzgl (96502)%27bad=", it can cause html injection.
|
|||||
| CVE-2022-32318 | 1 Fast Food Ordering System Project | 1 Fast Food Ordering System | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.
|
|||||
| CVE-2022-32308 | 1 Ublock Origin Project | 1 Ublock Origin | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process.
|
|||||
| CVE-2022-32286 | 1 Mendix | 1 Saml | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). In certain configurations SAML module is vulnerable to Cross Site Scripting (XSS) attacks due to insufficient error message sanitation. This could allow an attacker to execute malicious code by tricking users into accessing a malicious link.
|
|||||
| CVE-2022-32280 | 1 Xakuro | 1 Xo Slider | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Xakuro's XO Slider plugin <= 3.3.2 at WordPress.
|
|||||
| CVE-2022-32274 | 1 Ttpsc | 1 The Scheduler | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function.
|
|||||
| CVE-2022-32271 | 1 Realnetworks | 1 Realplayer | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
|
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.
|
|||||
| CVE-2022-32269 | 1 Realnetworks | 1 Realplayer | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.
|
|||||
| CVE-2022-32247 | 1 Sap | 1 Netweaver Enterprise Portal | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
|
|||||
| CVE-2022-32225 | 1 Veeam | 1 Management Pack | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for Microsoft System Center server, allowing for the execution of arbitrary scripts.
|
|||||
| CVE-2022-32195 | 1 Edx | 1 Open Edx | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
|
|||||
| CVE-2022-32173 | 1 Orchardcore | 1 Orchardcore | 2024-11-21 | N/A | 5.4 MEDIUM |
|
In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.
|
|||||
| CVE-2022-32172 | 1 Zinclabs | 1 Zinc | 2024-11-21 | N/A | N/A |
|
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
|
|||||
| CVE-2022-32171 | 1 Zinclabs | 1 Zinc | 2024-11-21 | N/A | N/A |
|
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to access the user’s credentials.
|
|||||
| CVE-2022-32167 | 1 Cloudreve | 1 Cloudreve | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.
|
|||||
| CVE-2022-32159 | 1 Infogami | 1 Infogami | 2024-11-21 | 3.5 LOW | N/A |
|
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.
|
|||||