Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25756 1 Siemens 48 Scalance X302-7eec, Scalance X302-7eec Firmware, Scalance X304-2fe and 45 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (2x 230V), ...

Show More

CVE-2022-25646 1 X-data-spreadsheet Project 1 X-data-spreadsheet 2024-11-21 N/A 5.4 MEDIUM
All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
CVE-2022-25642 1 Obyte 1 Obyte 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.
CVE-2022-25620 1 Profelis 1 Sambabox 2024-11-21 3.5 LOW 3.8 LOW
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.
CVE-2022-25618 1 Tms-outsource 1 Wpdatatables Lite 2024-11-21 3.5 LOW 3.4 LOW
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.1.27
CVE-2022-25617 1 Codesnippets 1 Code Snippets 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.
CVE-2022-25613 1 Foliovision 1 Fv Flowplayer Video Player 2024-11-21 3.5 LOW 4.1 MEDIUM
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
CVE-2022-25612 1 Presstigers 1 Simple Event Planner 2024-11-21 3.5 LOW 4.1 MEDIUM
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact].
CVE-2022-25611 1 Presstigers 1 Simple Event Planner 2024-11-21 3.5 LOW 4.1 MEDIUM
Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].
CVE-2022-25610 1 Plugin-planet 1 Simple Ajax Chat 2024-11-21 4.3 MEDIUM 3.4 LOW
Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit.
CVE-2022-25609 1 Yooslider 1 Yoo Slider 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with contributor or higher user role to inject the malicious code.
CVE-2022-25606 1 Wp-downloadmanager Project 1 Wp-downloadmanager 2024-11-21 3.5 LOW 4.8 MEDIUM
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.
CVE-2022-25605 1 Wp-downloadmanager Project 1 Wp-downloadmanager 2024-11-21 3.5 LOW 4.8 MEDIUM
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.
CVE-2022-25604 1 Price Table Project 1 Price Table 2024-11-21 3.5 LOW 4.1 MEDIUM
Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Price Table plugin (versions <= 0.2.2).
CVE-2022-25603 1 Maxfoundry 1 Maxgalleria 2024-11-21 3.5 LOW 4.8 MEDIUM
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5).
CVE-2022-25601 2 Fedoraproject, Plugin-planet 2 Fedora, Contact Form X 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
CVE-2022-25585 1 Unioncms Project 1 Unioncms 2024-11-21 3.5 LOW 5.4 MEDIUM
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
CVE-2022-25582 1 Classcms Project 1 Classcms 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field.
CVE-2022-25575 1 Hongmen 1 Parking Management System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification code text boxes.
CVE-2022-25574 1 Douco 1 Douphp 2024-11-21 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
CVE-2022-25507 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 3.5 LOW 5.4 MEDIUM
FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.
CVE-2022-25493 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
CVE-2022-25489 1 Thedigitalcraft 1 Atomcms 2024-11-21 3.5 LOW 5.4 MEDIUM
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
CVE-2022-25464 1 Html-js 1 Doracms 2024-11-21 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-25413 1 Max-3000 1 Maxsite Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
CVE-2022-25410 1 Max-3000 1 Maxsite Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
CVE-2022-25409 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 3.5 LOW 5.4 MEDIUM
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
CVE-2022-25408 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 3.5 LOW 5.4 MEDIUM
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.
CVE-2022-25407 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 3.5 LOW 5.4 MEDIUM
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.
CVE-2022-25395 1 Cosmetics And Beauty Product Online Store Project 1 Cosmetics And Beauty Product Online Store 2024-11-21 4.3 MEDIUM 9.6 CRITICAL
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.
CVE-2022-25373 1 Zohocorp 1 Manageengine Supportcenter Plus 2024-11-21 3.5 LOW 5.4 MEDIUM
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
CVE-2022-25370 1 Apache 1 Ofbiz 2024-11-21 N/A 5.4 MEDIUM
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.
CVE-2022-25349 1 Materializecss 1 Materialize 2024-11-21 4.3 MEDIUM 5.4 MEDIUM
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as &lt;not-a-tag /&gt;) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.
CVE-2022-25344 1 Olivetti 2 D-color Mf3555, D-color Mf3555 Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly check parameters, sent in a /dvcset/sysset/set.cgi POST request via the arg01.Hostname field, before saving them on the server. In addition, the JavaScript malicious content is then reflected back to the end user and executed by the web browser.
CVE-2022-25323 1 Zerof 1 Web Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
ZEROF Web Server 2.0 allows /admin.back XSS.
CVE-2022-25321 1 Cerebrate-project 1 Cerebrate 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
CVE-2022-25317 1 Cerebrate-project 1 Cerebrate 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
CVE-2022-25307 1 Veronalabs 1 Wp Statistics 2024-11-21 4.3 MEDIUM 7.2 HIGH
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.
CVE-2022-25306 1 Veronalabs 1 Wp Statistics 2024-11-21 4.3 MEDIUM 7.2 HIGH
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.
CVE-2022-25305 1 Veronalabs 1 Wp Statistics 2024-11-21 4.3 MEDIUM 7.2 HIGH
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.