Search Results (44001 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-46621 1 Enejbajgoric\/gagansandhu\/ctltdev 1 User Avatar 2024-11-21 6.1 Medium
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.
CVE-2023-46613 1 Add-to-calendar-button 1 Add To Calendar Button 2024-11-21 5.4 Medium
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <= 1.5.1 versions.
CVE-2023-46583 1 Phpgurukul 1 Nipah Virus Testing Management System 2024-11-21 6.1 Medium
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.
CVE-2023-46580 1 Code-projects 1 Inventory Management 2024-11-21 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
CVE-2023-46505 1 Pwncyn 1 Fancms 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 parameter in the demo.php file.
CVE-2023-46504 1 Pwncyn 1 Yxbookcms 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component.
CVE-2023-46503 1 Pwncyn 1 Yxbookcms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code via the reader management and book input modules.
CVE-2023-46495 1 Evershop 1 Evershop 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the sortBy parameter.
CVE-2023-46492 1 Mldb 1 Machine Learning Database 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.
CVE-2023-46491 1 Zentao 1 Biz 2024-11-21 6.1 Medium
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.
CVE-2023-46483 1 Timeteccloud 1 Auto Web-based Database Management System 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function.
CVE-2023-46475 1 Easycorp 1 Zentao 2024-11-21 5.4 Medium
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
CVE-2023-46470 1 Spaceapplications 1 Yacms 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser.
CVE-2023-46467 1 Juzaweb 1 Cms 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.
CVE-2023-46451 1 Mayurik 1 Best Courier Management System 2024-11-21 5.4 Medium
Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
CVE-2023-46450 1 Mayurik 1 Inventory Management System 2024-11-21 5.4 Medium
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
CVE-2023-46448 1 Dmpop 1 Mejiro 2024-11-21 6.1 Medium
Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.
CVE-2023-46396 1 Web-audimex 1 Audimex 2024-11-21 5.4 Medium
Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.
CVE-2023-46394 1 Gougucms 1 Gougucms 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
CVE-2023-46378 1 1234n 1 Minicms 2024-11-21 5.4 Medium
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.