Search Results (46975 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37786 1 Geeklog 1 Geeklog 2024-11-21 4.8 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Mail Settings[backend], Mail Settings[host], Mail Settings[port] and Mail Settings[auth] parameters of the /admin/configuration.php.
CVE-2023-37785 1 Impresscms 1 Impresscms 2024-11-21 4.8 Medium
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.
CVE-2023-37755 1 I-doit 1 I-doit 2024-11-21 9.8 Critical
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).
CVE-2023-37746 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter of the /admin/contactus.php component.
CVE-2023-37745 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Description of the /admin/aboutus.php component.
CVE-2023-37744 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 6.1 Medium
Maid Hiring Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-booking-request.php.
CVE-2023-37743 1 Phpgurukul 1 Teacher Subject Allocation System 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Teacher Subject Allocation System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search text box.
CVE-2023-37742 1 Webboss 1 Webboss.io Cms 2024-11-21 6.1 Medium
WebBoss.io CMS before v3.7.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVE-2023-37733 1 Tduckcloud 1 Tduck-platform 2024-11-21 6.1 Medium
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
CVE-2023-37728 1 Icewarp 1 Icewarp 2024-11-21 6.1 Medium
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
CVE-2023-37692 1 Octobercms 1 October 2024-11-21 5.4 Medium
An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.
CVE-2023-37690 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 4.8 Medium
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
CVE-2023-37689 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 4.8 Medium
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
CVE-2023-37688 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 4.8 Medium
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
CVE-2023-37686 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
CVE-2023-37685 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
CVE-2023-37684 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
CVE-2023-37683 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
CVE-2023-37658 1 Fastposter 1 Fast-poster 2024-11-21 5.4 Medium
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS
CVE-2023-37657 1 Lm21 1 Twonav 2024-11-21 5.4 Medium
TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).