Search Results (45575 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-35143 1 Jenkins 1 Maven Repository Server 2025-01-02 5.4 Medium
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`.
CVE-2023-28598 1 Zoom 1 Zoom 2025-01-02 7.5 High
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.
CVE-2023-28599 1 Zoom 1 Zoom 2025-01-02 4.3 Medium
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
CVE-2023-34121 2 Microsoft, Zoom 4 Windows, Rooms, Virtual Desktop Infrastructure and 1 more 2025-01-02 4.1 Medium
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.
CVE-2023-35145 1 Jenkins 1 Sonargraph Integration 2025-01-02 5.4 Medium
Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.
CVE-2024-56352 1 Jetbrains 1 Teamcity 2025-01-02 4.6 Medium
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
CVE-2024-56355 1 Jetbrains 1 Teamcity 2025-01-02 4.6 Medium
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
CVE-2022-21932 1 Microsoft 1 Dynamics 365 2025-01-02 7.6 High
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
CVE-2024-11111 1 Google 1 Chrome 2025-01-02 4.3 Medium
Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2024-11110 1 Google 1 Chrome 2025-01-02 6.5 Medium
Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
CVE-2024-11115 2 Apple, Google 2 Iphone Os, Chrome 2025-01-02 8.8 High
Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)
CVE-2024-11116 1 Google 1 Chrome 2025-01-02 4.3 Medium
Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2024-11117 1 Google 1 Chrome 2025-01-02 4.3 Medium
Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-43926 2 Fastlinemedia, The Beaver Builder Team 2 Beaver Builder, Beaver Builder 2025-01-02 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.
CVE-2024-55541 2025-01-02 N/A
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
CVE-2024-27104 1 Glpi-project 1 Glpi 2025-01-02 4.5 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13.
CVE-2024-27914 1 Glpi-project 1 Glpi 2025-01-02 5.3 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13.
CVE-2024-1474 1 Progress 1 Ws Ftp Server 2025-01-02 7.5 High
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
CVE-2023-35621 1 Microsoft 1 Dynamics 365 2025-01-01 7.5 High
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
CVE-2023-36020 1 Microsoft 1 Dynamics 365 2025-01-01 7.6 High
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability