Search Results (45575 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-29345 1 Microsoft 1 Edge Chromium 2025-01-01 6.1 Medium
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-36892 1 Microsoft 1 Sharepoint Server 2025-01-01 8 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-36869 1 Microsoft 1 Azure Devops Server 2025-01-01 6.3 Medium
Azure DevOps Server Spoofing Vulnerability
CVE-2023-29347 1 Microsoft 1 Windows Admin Center 2025-01-01 8.7 High
Windows Admin Center Spoofing Vulnerability
CVE-2023-21565 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Spoofing Vulnerability
CVE-2023-24896 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Dynamics 365 Finance Spoofing Vulnerability
CVE-2023-23383 1 Microsoft 1 Azure Service Fabric 2025-01-01 8.2 High
Service Fabric Explorer Spoofing Vulnerability
CVE-2023-21564 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Cross-Site Scripting Vulnerability
CVE-2023-21573 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21572 1 Microsoft 1 Dynamics 365 2025-01-01 6.5 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21571 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21570 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21806 1 Microsoft 1 Power Bi Report Server 2025-01-01 8.2 High
Power BI Report Server Spoofing Vulnerability
CVE-2024-43476 1 Microsoft 1 Dynamics 365 2024-12-31 7.6 High
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38221 1 Microsoft 1 Edge Chromium 2024-12-31 4.3 Medium
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-35146 1 Jenkins 1 Template Workflows 2024-12-31 5.4 Medium
Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.
CVE-2024-2071 1 Remyandrade 1 Faq Management System 2024-12-31 3.5 Low
A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affected by this issue is some unknown functionality of the component Update FAQ. The manipulation of the argument Frequently Asked Question leads to cross site scripting. The attack may be launched remotely. VDB-255386 is the identifier assigned to this vulnerability.
CVE-2024-27087 1 Getkirby 1 Kirby 2024-12-31 4.6 Medium
Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link to the relevant URL format. It also includes a "Custom" link type for advanced use cases that don't fit any of the pre-defined link formats. As the "Custom" link type is meant to be flexible, it also allows the javascript: URL scheme. In some use cases this can be intended, but it can also be misused by attackers to execute arbitrary JavaScript code when a user or visitor clicks on a link that is generated from the contents of the link field. This vulnerability is patched in 4.1.1.
CVE-2024-1749 1 Bdtask 1 Bhojon 2024-12-31 2.4 Low
A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Software 2.9. This issue affects some unknown processing of the file /dashboard/message of the component Message Page. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254531. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-0010 1 Paloaltonetworks 1 Pan-os 2024-12-30 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.