Search Results (45914 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-33021 1 Xarrow 1 Xarrow 2025-04-16 6.1 Medium
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
CVE-2021-33025 1 Xarrow 1 Xarrow 2025-04-16 5.6 Medium
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
CVE-2021-32962 1 Aggsoft 1 Webserver 2025-04-16 8.2 High
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.
CVE-2021-32989 1 Lcds 1 Laquis Scada 2025-04-16 9.3 Critical
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
CVE-2021-33016 1 Kuka 3 Kr C4, Kr C4 Firmware, Kss 2025-04-16 9.8 Critical
An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.
CVE-2020-36547 1 Ge 2 Voluson S8, Voluson S8 Firmware 2025-04-16 5.9 Medium
A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change the configuration settings.
CVE-2022-2254 1 Webhmi 2 Webhmi, Webhmi Firmware 2025-04-16 6.2 Medium
A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 can store a script that could impact other logged in users.
CVE-2021-43657 1 Simple Client Management System Project 1 Simple Client Management System 2025-04-16 5.4 Medium
A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.
CVE-2022-2107 1 Micodus 2 Mv720, Mv720 Firmware 2025-04-16 9.8 Critical
The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.
CVE-2022-38069 1 Contechealth 2 Cms8000, Cms8000 Firmware 2025-04-16 4.3 Medium
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters
CVE-2019-18265 1 Digitalalertsystems 10 Dasdec I, Dasdec I Firmware, Dasdec Ii and 7 more 2025-04-16 4.7 Medium
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.
CVE-2022-40204 1 Digitalalertsystems 10 Dasdec I, Dasdec I Firmware, Dasdec Ii and 7 more 2025-04-16 4.1 Medium
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
CVE-2022-41653 1 Daikinlatam 2 Svmpc1, Svmpc2 2025-04-16 9.8 Critical
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.
CVE-2022-2660 1 Deltaww 1 Dialink 2025-04-16 9.8 Critical
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
CVE-2023-49987 1 Oretnom23 1 School Fees Management System 2025-04-16 5.4 Medium
A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.
CVE-2024-28623 1 Ritecms 1 Ritecms 2025-04-16 6.1 Medium
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
CVE-2022-22748 2 Mozilla, Redhat 6 Firefox, Firefox Esr, Thunderbird and 3 more 2025-04-16 6.5 Medium
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2020-15718 1 Rosariosis 1 Rosariosis 2025-04-16 6.1 Medium
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.
CVE-2020-15716 1 Rosariosis 1 Rosariosis 2025-04-16 6.1 Medium
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.
CVE-2018-25080 1 Mobiledetect 1 Mobiledetect 2025-04-16 3.5 Low
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.8.32 is able to address this issue. The identifier of the patch is 31818a441b095bdc4838602dbb17b8377d1e5cce. It is recommended to upgrade the affected component. The identifier VDB-220061 was assigned to this vulnerability.