Export limit exceeded: 375115 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 48018 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48018 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-43500 | 1 Wordpress | 1 Wordpress | 2025-04-24 | 6.1 Medium |
| Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | ||||
| CVE-2022-43499 | 1 Ss-proj | 1 Shirasagi | 2025-04-24 | 5.4 Medium |
| Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. | ||||
| CVE-2022-43497 | 1 Wordpress | 1 Wordpress | 2025-04-24 | 6.1 Medium |
| Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | ||||
| CVE-2022-43487 | 1 Salonbookingsystem | 1 Salon Booking System | 2025-04-24 | 6.1 Medium |
| Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script. | ||||
| CVE-2021-34181 | 1 Tomexam | 1 Tomexam | 2025-04-24 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml. | ||||
| CVE-2022-46089 | 2 Oretnom23, Sourcecodester | 2 Online Flight Booking Management System, Online Flight Booking Management System | 2025-04-24 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter. | ||||
| CVE-2025-2946 | 1 Pgadmin | 1 Pgadmin 4 | 2025-04-23 | 9.1 Critical |
| pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser. | ||||
| CVE-2024-55000 | 1 Mayurik | 1 House Rental Management System | 2025-04-23 | 5.4 Medium |
| Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php. | ||||
| CVE-2024-56115 | 1 Amiro | 1 Amiro.cms | 2025-04-23 | 6.1 Medium |
| A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a Cross-Site Scripting (XSS) attack. | ||||
| CVE-2024-43437 | 1 Moodle | 1 Moodle | 2025-04-23 | 5.4 Medium |
| A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. | ||||
| CVE-2024-43439 | 1 Moodle | 1 Moodle | 2025-04-23 | 5.4 Medium |
| A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. | ||||
| CVE-2021-37191 | 1 Siemens | 1 Sinema Remote Connect Server | 2025-04-23 | 4.3 Medium |
| A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software. | ||||
| CVE-2022-40603 | 1 Zyxel | 38 Atp100, Atp100 Firmware, Atp100w and 35 more | 2025-04-23 | 4.7 Medium |
| A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser. | ||||
| CVE-2024-5520 | 1 Alkacon | 1 Opencms | 2025-04-23 | 6.4 Medium |
| Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field. | ||||
| CVE-2021-21079 | 1 Adobe | 1 Connect | 2025-04-23 | 6.1 Medium |
| Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious JavaScript content that may be executed within the context of the victim's browser when they browse to the page containing the vulnerable field. | ||||
| CVE-2021-21080 | 1 Adobe | 1 Connect | 2025-04-23 | 6.1 Medium |
| Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious JavaScript content that may be executed within the context of the victim's browser when they browse to the page containing the vulnerable field. | ||||
| CVE-2021-21087 | 1 Adobe | 1 Coldfusion | 2025-04-23 | 5.4 Medium |
| Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction. | ||||
| CVE-2023-25836 | 1 Esri | 1 Portal For Arcgis | 2025-04-23 | 5.4 Medium |
| There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are low. | ||||
| CVE-2023-25831 | 1 Esri | 1 Portal For Arcgis | 2025-04-23 | 6.1 Medium |
| There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | ||||
| CVE-2023-25830 | 1 Esri | 1 Portal For Arcgis | 2025-04-23 | 6.1 Medium |
| There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | ||||