Export limit exceeded: 44783 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (44783 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-43436 1 Iresturant Project 1 Iresturant 2024-11-21 5.4 Medium
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
CVE-2021-43432 1 Exrick 1 Xmall 2024-11-21 6.1 Medium
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.
CVE-2021-43409 1 Wpo365 1 Wordpress \+ Azure Ad \/ Microsoft Office 365 2024-11-21 9.3 Critical
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data. In this case, the XSS payload can be submitted by any anonymous user, the payload then renders and executes when a WordPress administrator authenticates and accesses the WordPress Dashboard. The injected payload can carry out actions on behalf of the administrator including adding other administrative users and changing application settings. This flaw could be exploited to ultimately provide full control of the affected system to the attacker.
CVE-2021-43334 1 Buddyboss 1 Buddyboss 2024-11-21 5.4 Medium
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
CVE-2021-43331 2 Debian, Gnu 2 Debian Linux, Mailman 2024-11-21 6.1 Medium
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
CVE-2021-43324 1 Librenms 1 Librenms 2024-11-21 6.1 Medium
LibreNMS through 21.10.2 allows XSS via a widget title.
CVE-2021-43295 1 Zohocorp 1 Manageengine Supportcenter Plus 2024-11-21 6.1 Medium
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
CVE-2021-43294 1 Zohocorp 1 Manageengine Supportcenter Plus 2024-11-21 6.1 Medium
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
CVE-2021-43288 1 Thoughtworks 1 Gocd 2024-11-21 5.4 Medium
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.
CVE-2021-43284 1 Govicture 2 Wr1200, Wr1200 Firmware 2024-11-21 7.8 High
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).
CVE-2021-43282 1 Govicture 2 Wr1200, Wr1200 Firmware 2024-11-21 6.5 Medium
An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.
CVE-2021-43265 1 Mahara 1 Mahara 2024-11-21 5.4 Medium
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
CVE-2021-43198 1 Jetbrains 1 Teamcity 2024-11-21 5.4 Medium
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
CVE-2021-43197 1 Jetbrains 1 Teamcity 2024-11-21 6.1 Medium
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
CVE-2021-43186 1 Jetbrains 1 Youtrack 2024-11-21 5.4 Medium
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
CVE-2021-43184 1 Jetbrains 1 Youtrack 2024-11-21 5.4 Medium
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
CVE-2021-43181 1 Jetbrains 1 Hub 2024-11-21 6.1 Medium
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
CVE-2021-43154 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
CVE-2021-43137 1 Phpgurukul 1 Hostel Management System 2024-11-21 8.8 High
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
CVE-2021-43136 1 Formalms 1 Formalms 2024-11-21 9.8 Critical
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.