Search Results (44243 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-1074 1 Fastlinemedia 1 Beaver Builder 2025-01-02 6.4 Medium
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the audio widget 'link_url' parameter in all versions up to, and including, 2.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-55541 2025-01-02 N/A
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
CVE-2024-56263 2025-01-02 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Shots for Dribbble allows DOM-Based XSS.This issue affects GS Shots for Dribbble: from n/a through 1.2.0.
CVE-2024-1080 1 Fastlinemedia 1 Beaver Builder 2025-01-02 6.4 Medium
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via the heading tag in all versions up to, and including, 2.7.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-56267 2025-01-02 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.com Interactive UK Map allows Stored XSS.This issue affects Interactive UK Map: from n/a through 3.4.8.
CVE-2024-56302 2025-01-02 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ConvertCalculator ConvertCalculator for WordPress allows Stored XSS.This issue affects ConvertCalculator for WordPress: from n/a through 1.1.1.
CVE-2024-56268 2025-01-02 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hait Post Grid Elementor Addon allows Stored XSS.This issue affects Post Grid Elementor Addon: from n/a through 2.0.18.
CVE-2024-27104 1 Glpi-project 1 Glpi 2025-01-02 4.5 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13.
CVE-2024-27914 1 Glpi-project 1 Glpi 2025-01-02 5.3 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13.
CVE-2024-56023 2025-01-02 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfect Solution WP eCommerce Quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through 1.1.0.
CVE-2024-1474 1 Progress 1 Ws Ftp Server 2025-01-02 7.5 High
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
CVE-2023-35621 1 Microsoft 1 Dynamics 365 2025-01-01 7.5 High
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
CVE-2023-36020 1 Microsoft 1 Dynamics 365 2025-01-01 7.6 High
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-29345 1 Microsoft 1 Edge Chromium 2025-01-01 6.1 Medium
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-36892 1 Microsoft 1 Sharepoint Server 2025-01-01 8 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-36869 1 Microsoft 1 Azure Devops Server 2025-01-01 6.3 Medium
Azure DevOps Server Spoofing Vulnerability
CVE-2023-29347 1 Microsoft 1 Windows Admin Center 2025-01-01 8.7 High
Windows Admin Center Spoofing Vulnerability
CVE-2023-21565 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Spoofing Vulnerability
CVE-2023-24896 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Dynamics 365 Finance Spoofing Vulnerability
CVE-2023-23383 1 Microsoft 1 Azure Service Fabric 2025-01-01 8.2 High
Service Fabric Explorer Spoofing Vulnerability