Search Results (46986 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-40984 1 Webmin 1 Webmin 2024-11-21 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file.
CVE-2023-40983 1 Webmin 1 Webmin 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file.
CVE-2023-40982 1 Webmin 1 Webmin 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter.
CVE-2023-40932 1 Nagios 1 Nagios Xi 2024-11-21 5.4 Medium
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
CVE-2023-40877 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
CVE-2023-40876 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.
CVE-2023-40875 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.
CVE-2023-40874 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.
CVE-2023-40869 1 Moosocial 1 Moosocial 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.
CVE-2023-40851 1 User Registration \& Login And User Management System With Admin Panel Project 1 User Registration \& Login And User Management System With Admin Panel 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.
CVE-2023-40817 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
CVE-2023-40816 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
CVE-2023-40815 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.
CVE-2023-40814 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
CVE-2023-40813 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.
CVE-2023-40812 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.
CVE-2023-40810 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
CVE-2023-40809 1 Opencrx 1 Opencrx 2024-11-21 6.1 Medium
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
CVE-2023-40786 1 Hkcms 1 Hkcms 2024-11-21 5.4 Medium
HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen.
CVE-2023-40755 1 Phpjabbers 1 Callback Widget 2024-11-21 6.1 Medium
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.