Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-43263 | 1 Guitar-pro | 1 Guitar Pro | 2022-11-16 | N/A | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file. | |||||
CVE-2022-44071 | 1 Tribalsystems | 1 Zenario | 2022-11-16 | N/A | 5.4 MEDIUM |
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile. | |||||
CVE-2022-44070 | 1 Tribalsystems | 1 Zenario | 2022-11-16 | N/A | 5.4 MEDIUM |
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles. | |||||
CVE-2022-44073 | 1 Tribalsystems | 1 Zenario | 2022-11-16 | N/A | 5.4 MEDIUM |
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts. | |||||
CVE-2022-44069 | 1 Tribalsystems | 1 Zenario | 2022-11-16 | N/A | 5.4 MEDIUM |
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module. | |||||
CVE-2022-34317 | 1 Ibm | 1 Cics Tx | 2022-11-16 | N/A | 5.4 MEDIUM |
IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229459. | |||||
CVE-2022-3631 | 1 Digitialpixies | 1 Oauth Client | 2022-11-16 | N/A | 4.8 MEDIUM |
The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |||||
CVE-2022-3578 | 1 Metagauss | 1 Profilegrid | 2022-11-16 | N/A | 6.1 MEDIUM |
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-3539 | 1 Themepoints | 2 Testimonials, Testimonials Pro | 2022-11-16 | N/A | 4.8 MEDIUM |
The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-3469 | 1 Wp Attachments Project | 1 Wp Attachments | 2022-11-16 | N/A | 4.8 MEDIUM |
The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |||||
CVE-2022-3415 | 1 Bluecoral | 1 Chat Bubble | 2022-11-16 | N/A | 6.1 MEDIUM |
The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message | |||||
CVE-2022-3988 | 1 Frappe | 1 Frappe | 2022-11-16 | N/A | 6.1 MEDIUM |
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting. The attack may be launched remotely. The name of the patch is bfab7191543961c6cb77fe267063877c31b616ce. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213560. | |||||
CVE-2022-41905 | 1 Wsgidav Project | 1 Wsgidav | 2022-11-16 | N/A | 6.1 MEDIUM |
WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set `dir_browser.enable = False` in the configuration. | |||||
CVE-2022-43754 | 2 Suse, Uyuni-project | 2 Manager Server, Uyuni | 2022-11-16 | N/A | 5.4 MEDIUM |
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.2 allows remote attackers to embed Javascript code via /rhn/audit/scap/Search.do This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.2 hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.25.2, locale-formula-0.3-150300.3.3.2, py27-compat-salt-3000.3-150300.7.7.26.2, python-urlgrabber-3.10.2.1py2_3-150300.3.3.2, spacecmd-4.2.20-150300.4.30.2, spacewalk-backend-4.2.25-150300.4.32.4, spacewalk-client-tools-4.2.21-150300.4.27.3, spacewalk-java-4.2.43-150300.3.48.2, spacewalk-utils-4.2.18-150300.3.21.2, spacewalk-web-4.2.30-150300.3.30.3, susemanager-4.2.38-150300.3.44.3, susemanager-doc-indexes-4.2-150300.12.36.3, susemanager-docs_en-4.2-150300.12.36.2, susemanager-schema-4.2.25-150300.3.30.3, susemanager-sls versions prior to 4.2.28. SUSE Linux Enterprise Module for SUSE Manager Server 4.3 spacewalk-java versions prior to 4.3.39. SUSE Manager Server 4.2 release-notes-susemanager versions prior to 4.2.10. | |||||
CVE-2022-1566 | 1 Quotes Llama Project | 1 Quotes Llama | 2022-11-16 | 3.5 LOW | 4.8 MEDIUM |
The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV file | |||||
CVE-2021-24444 | 1 Taxopress | 1 Taxopress | 2022-11-16 | 3.5 LOW | 4.8 MEDIUM |
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue. | |||||
CVE-2018-19956 | 1 Qnap | 1 Photo Station | 2022-11-16 | 4.3 MEDIUM | 6.1 MEDIUM |
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10. | |||||
CVE-2018-19955 | 1 Qnap | 1 Photo Station | 2022-11-16 | 4.3 MEDIUM | 6.1 MEDIUM |
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10. | |||||
CVE-2018-19954 | 1 Qnap | 1 Photo Station | 2022-11-16 | 4.3 MEDIUM | 6.1 MEDIUM |
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10. | |||||
CVE-2018-19951 | 1 Qnap | 2 Music Station, Qts | 2022-11-16 | 4.3 MEDIUM | 6.1 MEDIUM |
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11. |