Latest CVE Feed
-
5.4
MEDIUMCVE-2023-43344
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the SEO - Meta description parameter in the Pages Menu component.... Read more
Affected Products : quick_cms- Published: Oct. 19, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43359
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.... Read more
Affected Products : cms_made_simple- Published: Oct. 19, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41893
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication will be ... Read more
Affected Products : home-assistant- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-45471
The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious w... Read more
Affected Products : search_server- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-4923
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated atta... Read more
Affected Products : bear_-_woocommerce_bulk_editor_and_products_manager_professional- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43354
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.... Read more
Affected Products : cms_made_simple- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43356
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.... Read more
Affected Products : cms_made_simple- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43346
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.... Read more
Affected Products : quick_cms- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46003
I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.... Read more
Affected Products : i-doit- Published: Oct. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46054
Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.... Read more
Affected Products : wbce_cms- Published: Oct. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-22125
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with netw... Read more
Affected Products : banking_trade_finance- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-22124
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with netw... Read more
Affected Products : banking_trade_finance- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44769
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.... Read more
Affected Products : zenario- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46450
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.... Read more
Affected Products : inventory_management_system- Published: Oct. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-2405
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.... Read more
Affected Products : solution_manager- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46858
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post... Read more
Affected Products : moodle- Published: Oct. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46040
Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function.... Read more
Affected Products : getsimplecms- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-6904
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.... Read more
Affected Products : car_rental_script- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44954
Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions.... Read more
Affected Products : bigtree_cms- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-9999
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.... Read more
Affected Products : zulip_server- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024