Export limit exceeded: 47992 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (47992 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-7149 1 B2evolution 1 B2evolution 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to the autolink function.
CVE-2017-0195 1 Microsoft 5 Excel Web App, Office Online Server, Office Web Apps and 2 more 2025-04-20 N/A
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."
CVE-2016-4946 1 Cloudera 1 Hue 2025-04-20 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in the HUE Users page.
CVE-2016-4930 1 Juniper 1 Junos Space 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
CVE-2016-4888 1 Zohocorp 1 Servicedesk Plus 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-4865 1 Cybozu 1 Office 2025-04-20 N/A
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
CVE-2016-9358 1 Marel 44 A320, A320 Firmware, A325 and 41 more 2025-04-20 N/A
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. The end user does not have the ability to change system passwords.
CVE-2024-31828 1 Lavalite 1 Lavalite 2025-04-18 6.1 Medium
Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.
CVE-2024-31741 2 1234n, Minicms Project 2 Minicms, Minicms 2025-04-18 6.1 Medium
Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.
CVE-2024-2603 1 Salonbookingsystem 1 Salon Booking System 2025-04-18 6.3 Medium
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-31609 2 Bosscms, Code-projects 2 Bosscms, Simple School Management System 2025-04-18 7.1 High
Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.
CVE-2024-55342 1 Dotnetfoundation 1 Piranha Cms 2025-04-18 4.7 Medium
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability.
CVE-2020-22540 1 Codologic 1 Codoforum 2025-04-18 5.4 Medium
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.
CVE-2024-4061 1 Ays-pro 1 Survey Maker 2025-04-18 4.8 Medium
The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-38653 1 Hcltech 1 Digital Experience 2025-04-18 2 Low
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
CVE-2024-51055 1 Hoosk 1 Hoosk 2025-04-18 6.5 Medium
An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.
CVE-2023-46950 1 Contribsys 1 Sidekiq 2025-04-18 6.1 Medium
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.
CVE-2022-37832 1 Mutiny 1 Mutiny 2025-04-18 9.8 Critical
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
CVE-2022-36223 1 Emby 1 Emby 2025-04-18 6.1 Medium
In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.
CVE-2024-24511 1 Pkp.sfu 1 Open Journal Systems 2025-04-18 6.1 Medium
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.