Export limit exceeded: 37079 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (37079 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-42790 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2024-09-05 6.1 Medium
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.
CVE-2024-42792 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2024-09-05 3.5 Low
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.
CVE-2024-42906 2 Jenkins, Testlink 2 Testlink, Testlink 2024-09-05 4.1 Medium
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
CVE-2024-44793 1 Gazelle Project 1 Gazelle 2024-09-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.
CVE-2024-44794 2 Picuploader, Xiebruce 2 Commit, Picuploader 2024-09-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
CVE-2024-44795 1 Gazelle Project 1 Gazelle 2024-09-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
CVE-2024-43961 1 Azurecurve 1 Toggle Show\/hide 2024-09-05 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Toggle Show/Hide: from n/a through 2.1.3.
CVE-2024-8194 1 Google 1 Chrome 2024-09-05 7.5 High
Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-8193 1 Google 1 Chrome 2024-09-05 8.8 High
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-45046 2 Phpoffice, Phpspreadsheet Project 2 Phpspreadsheet, Phpspreadsheet 2024-09-04 5.4 Medium
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpreadsheet\Writer\Html` doesn't sanitize spreadsheet styling information such as font names, allowing an attacker to inject arbitrary JavaScript on the page. As a result an attacker may used a crafted spreadsheet to fully takeover a session of a user viewing spreadsheet files as HTML. This issue has been addressed in release version 2.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-45048 2 Phpoffice, Phpspreadsheet Project 2 Phpspreadsheet, Phpspreadsheet 2024-09-04 8.8 High
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This vulnerability has been addressed in release version 2.2.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-41371 1 Organizr 1 Organizr 2024-09-04 6.1 Medium
Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
CVE-2024-41351 1 Baijunyao 2 Bjyadmin, Thinkphp-bjyadmin 2024-09-04 6.1 Medium
bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php
CVE-2024-41350 1 Baijunyao 2 Bjyadmin, Thinkphp-bjyadmin 2024-09-04 6.1 Medium
bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php
CVE-2024-43921 1 Magic-post-thumbnail 1 Magic Post Thumbnail 2024-09-04 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9.
CVE-2024-43920 1 Jegstudio 1 Gutenverse 2024-09-04 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.4.
CVE-2024-44778 1 Vtiger 1 Vtiger Crm 2024-09-03 7.4 High
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-44779 1 Vtiger 1 Vtiger Crm 2024-09-03 7.4 High
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-44777 1 Vtiger 1 Vtiger Crm 2024-09-03 7.4 High
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-43964 1 Dsgvo-for-wp 1 Dsgvo All In One For Wp 2024-09-03 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This issue affects DSGVO All in one for WP: from n/a through 4.5.