Export limit exceeded: 45437 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (45437 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41657 1 Groundhogg 1 Hollerbox 2024-11-21 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. HollerBox plugin <= 2.3.2 versions.
CVE-2023-41653 1 Bearthemes 1 Sermon\'e - Sermons Online 2024-11-21 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
CVE-2023-41642 1 Grupposcai 1 Realgimm 2024-11-21 6.1 Medium
Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.
CVE-2023-41616 1 Student Management System Project 1 Student Management System 2024-11-21 4.8 Medium
A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3 and before allows attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload.
CVE-2023-41614 1 Phpgurukul 1 Zoo Management System 2024-11-21 4.8 Medium
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.
CVE-2023-41601 1 Cszcms 1 Csz Cms 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters.
CVE-2023-41597 1 Eyoucms 1 Eyoucms 2024-11-21 6.1 Medium
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
CVE-2023-41595 1 Vaxilu 1 X-ui 2024-11-21 7.5 High
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
CVE-2023-41593 1 Phpgurukul 1 Dairy Farm Shop Management System 2024-11-21 5.4 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.
CVE-2023-41592 1 Froala 1 Froala Editor 2024-11-21 5.4 Medium
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-41588 1 Appfire 1 Time To Sla 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Time to SLA plugin v10.13.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the durationFormat parameter.
CVE-2023-41575 1 Phpgurukul 1 Blood Bank \& Donor Management System 2024-11-21 5.4 Medium
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
CVE-2023-41538 1 Phpjabbers 1 Php Forum Script 2024-11-21 6.1 Medium
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
CVE-2023-41508 1 Superstorefinder 1 Super Store Finder 2024-11-21 9.8 Critical
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
CVE-2023-41453 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.
CVE-2023-41451 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
CVE-2023-41448 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.
CVE-2023-41447 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.
CVE-2023-41446 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
CVE-2023-41445 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.