Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-4029 | 1 Simple-press | 1 Simple\ | 2022-12-01 | N/A | 4.7 MEDIUM |
The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This would be highly complex to exploit as it would require the attacker to set the cookie a cookie for the targeted user. | |||||
CVE-2022-4028 | 1 Simple-press | 1 Simple\ | 2022-12-01 | N/A | 5.4 MEDIUM |
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and embed tags possible. This makes it possible for authenticated attackers, with minimal permissions, such as a subscriber to inject arbitrary web scripts in pages when modifying a profile signature that will execute whenever a user accesses an injected page. | |||||
CVE-2022-45225 | 1 Book Store Management System Project | 1 Book Store Management System | 2022-12-01 | N/A | 6.1 MEDIUM |
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter. | |||||
CVE-2022-39333 | 1 Nextcloud | 1 Desktop | 2022-12-01 | N/A | 6.1 MEDIUM |
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. | |||||
CVE-2022-39332 | 1 Nextcloud | 1 Desktop | 2022-12-01 | N/A | 5.4 MEDIUM |
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. | |||||
CVE-2022-39325 | 1 Basercms | 1 Basercms | 2022-12-01 | N/A | 6.1 MEDIUM |
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability. | |||||
CVE-2022-41706 | 1 Spatie | 1 Browsershot | 2022-12-01 | N/A | 8.2 HIGH |
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method. | |||||
CVE-2022-41676 | 1 Raidenmaild | 1 Raidenmaild | 2022-12-01 | N/A | 5.4 MEDIUM |
Raiden MAILD Mail Server website mail field has insufficient filtering for user input. A remote attacker with general user privilege can send email using the website with malicious JavaScript in the input field, which triggers XSS (Reflected Cross-Site Scripting) attack to the mail recipient. | |||||
CVE-2022-39331 | 1 Nextcloud | 1 Desktop | 2022-12-01 | N/A | 5.4 MEDIUM |
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. | |||||
CVE-2019-6565 | 1 Moxa | 8 Eds-405a, Eds-405a Firmware, Eds-408a and 5 more | 2022-11-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability to perform XSS attacks, which may be used to send a malicious script. | |||||
CVE-2019-6562 | 1 Philips | 1 Tasy Emr | 2022-11-30 | 3.5 LOW | 5.4 MEDIUM |
In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. | |||||
CVE-2019-6835 | 1 Schneider-electric | 8 Meg6260-0410, Meg6260-0410 Firmware, Meg6260-0415 and 5 more | 2022-11-30 | 3.5 LOW | 5.4 MEDIUM |
A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to inject client-side script when a user visits a web page. | |||||
CVE-2022-4091 | 1 Canteen Management System Project | 1 Canteen Management System | 2022-11-30 | N/A | 6.1 MEDIUM |
A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function query of the file food.php. The manipulation of the argument product_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214359. | |||||
CVE-2022-0698 | 1 Microweber | 1 Microweber | 2022-11-30 | N/A | 6.1 MEDIUM |
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. | |||||
CVE-2022-38147 | 1 Silverstripe | 1 Framework | 2022-11-30 | N/A | 5.4 MEDIUM |
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). | |||||
CVE-2022-37421 | 1 Silverstripe | 1 Silverstripe | 2022-11-30 | N/A | 5.4 MEDIUM |
Silverstripe silverstripe/cms through 4.11.0 allows XSS. | |||||
CVE-2022-42095 | 1 Backdropcms | 1 Backdrop Cms | 2022-11-30 | N/A | 4.8 MEDIUM |
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content. | |||||
CVE-2022-38145 | 1 Silverstripe | 1 Framework | 2022-11-30 | N/A | 5.4 MEDIUM |
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view. | |||||
CVE-2022-37430 | 1 Silverstripe | 1 Framework | 2022-11-30 | N/A | 5.4 MEDIUM |
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). | |||||
CVE-2022-45214 | 1 Sanitization Management System Project | 1 Sanitization Management System | 2022-11-29 | N/A | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter at /php-sms/classes/Login.php. |