Export limit exceeded: 47885 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 48083 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (48083 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-10482 2 Tinysolutions, Wptinysolutions 2 Media Library Tools, Media Library Tools 2025-05-15 5.4 Medium
The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
CVE-2024-24059 1 Aitangbao 1 Springboot-manager 2025-05-15 6.1 Medium
springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.
CVE-2024-22927 1 Eyoucms 1 Eyoucms 2025-05-15 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
CVE-2022-38902 1 Liferay 2 Dxp, Liferay Portal 2025-05-15 5.4 Medium
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
CVE-2022-35612 1 Bevywise 1 Mqttroute 2025-05-15 5.4 Medium
A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field.
CVE-2022-35134 1 Boodskap 1 Iot Platform 2025-05-15 5.4 Medium
Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.
CVE-2024-9600 1 Metaphorcreations 1 Ditty 2025-05-15 4.8 Medium
The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks.
CVE-2024-6393 1 Imagely 1 Nextgen Gallery 2025-05-15 4.8 Medium
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-41540 1 Tp-link 2 Ax10, Ax10 Firmware 2025-05-15 5.9 Medium
The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to intercept the communications between the web client and router through a man-in-the-middle attack can then obtain the sequence key via a brute-force attack, and access sensitive information.
CVE-2022-41473 1 Rpcms 1 Rpcms 2025-05-15 6.1 Medium
RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
CVE-2022-41391 1 Ocomon Project 1 Ocomon 2025-05-15 9.8 Critical
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
CVE-2022-41351 1 Zimbra 1 Collaboration 2025-05-15 6.1 Medium
In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default value of 10).
CVE-2022-41350 1 Zimbra 1 Collaboration 2025-05-15 6.1 Medium
In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
CVE-2022-41349 1 Zimbra 1 Collaboration 2025-05-15 6.1 Medium
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
CVE-2022-41348 1 Zimbra 1 Collaboration 2025-05-15 6.1 Medium
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.
CVE-2024-10471 1 Wpeverest 1 Everest Forms 2025-05-15 4.8 Medium
The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-3630 1 Dachande663 1 Hl Twitter 2025-05-15 5.4 Medium
The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-2220 1 Buttonizer 1 Call \/ Chat \/ Contact Button 2025-05-15 3.5 Low
The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-3822 1 Mranderson 1 Base64 Encoder\/decoder 2025-05-15 4.8 Medium
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2025-2377 1 Janobe 1 Vehicle Management System 2025-05-14 3.5 Low
A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /confirmbooking.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting product names.