βΌ CVE-2023-25044 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <=Γ 4.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1279 βΌ
π Read
via "National Vulnerability Database".
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40970 βΌ
π Read
via "National Vulnerability Database".
Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25488 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Duc Bui Quang WP Default Feature Image plugin <=Γ 1.0.1.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24412 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Image Social Feed plugin <=Γ 1.7.6 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4704 βΌ
π Read
via "National Vulnerability Database".
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.π Read
via "National Vulnerability Database".
βΌ CVE-2022-4343 βΌ
π Read
via "National Vulnerability Database".
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39685 βΌ
π Read
via "National Vulnerability Database".
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37827 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the executionBlockName parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22305 βΌ
π Read
via "National Vulnerability Database".
An improper certificate validation vulnerability [CWE-295] inΓ FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker toΓ man-in-the-middle the communication between the listed products and some external peers.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37986 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On Γ’β¬β YM SSO Login plugin <=Γ 1.1.3 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37828 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tasktyp parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37893 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chop-Chop Coming Soon Chop Chop plugin <=Γ 2.2.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-34011 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ShopConstruct plugin <=Γ 1.1.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37994 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Artem Abramovich Art Decoration Shortcode plugin <=Γ 1.5.6 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37830 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39703 βΌ
π Read
via "National Vulnerability Database".
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading a crafted Markdown file.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37826 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fieldname parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37997 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dharmesh Patel Post List With Featured Image plugin <=Γ 1.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37829 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notification.message parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39710 βΌ
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.π Read
via "National Vulnerability Database".