Search Results (43859 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-43144 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 5.4 Medium
A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-41434 1 Eyesofnetwork 1 Web Interface 2025-05-01 6.1 Medium
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.
CVE-2022-41433 1 Eyesofnetwork 1 Web Interface 2025-05-01 4.8 Medium
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php.
CVE-2022-41432 1 Eyesofnetwork 1 Web Interface 2025-05-01 4.8 Medium
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php.
CVE-2021-40289 1 Mm-wki Project 1 Mm-wki 2025-05-01 6.1 Medium
mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-3873 1 Diagrams 1 Drawio 2025-05-01 6.1 Medium
Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2.
CVE-2023-4148 1 Metaphorcreations 1 Ditty 2025-05-01 6.1 Medium
The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2022-43321 1 Shopwind 1 Shopwind 2025-05-01 6.1 Medium
Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.
CVE-2022-43320 1 Feehi 1 Feehicms 2025-05-01 6.1 Medium
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
CVE-2022-43121 1 Intelliants 1 Subrion Cms 2025-05-01 6.1 Medium
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
CVE-2022-43118 1 Flatcore 1 Flatcore-cms 2025-05-01 6.1 Medium
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.
CVE-2022-31688 1 Vmware 1 Workspace One Assist 2025-05-01 6.1 Medium
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
CVE-2021-40303 1 Perfexcrm 1 Perfex Crm 2025-05-01 5.4 Medium
perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
CVE-2022-43120 1 Intelliants 1 Subrion Cms 2025-05-01 6.1 Medium
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
CVE-2022-33322 1 Mitsubishielectric 238 Ma-ew85s-e, Ma-ew85s-e Firmware, Ma-ew85s-uk and 235 more 2025-05-01 6.1 Medium
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
CVE-2023-0878 1 Nuxt 1 Nuxt 2025-05-01 6.1 Medium
Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.
CVE-2024-29374 1 Moodle 1 Moodle 2025-05-01 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
CVE-2023-7167 1 Danialhatami 1 Persian Fonts 2025-05-01 6.1 Medium
The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-48743 2 Tektronix, Telestream 2 Sentry, Sentry 2025-05-01 6.5 Medium
Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.
CVE-2024-10276 1 Telestream 1 Sentry 2025-05-01 3.5 Low
A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.