Filtered by vendor
Subscriptions
Total
44986 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-24803 | 1 Opensecurity | 1 Mobile Security Framework | 2025-07-07 | 5.4 Medium |
| Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.). However, an attacker can manually modify this value in the `Info.plist` file and add special characters to the `<key>CFBundleIdentifier</key>` value. The `dynamic_analysis.html` file does not sanitize the received bundle value from Corellium and as a result, it is possible to break the HTML context and achieve Stored XSS. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
| CVE-2025-6613 | 2 Anujk305, Phpgurukul | 2 Hospital Management System, Hospital Management System | 2025-07-07 | 3.5 Low |
| A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functionality of the file /doctor/manage-patient.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2018-13065 | 1 Owasp | 1 Modsecurity | 2025-07-03 | N/A |
| ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured | ||||
| CVE-2024-35545 | 1 Mapos | 1 Map-os | 2025-07-03 | 6.1 Medium |
| MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability. | ||||
| CVE-2024-36819 | 1 Mapos | 1 Map-os | 2025-07-03 | 5.4 Medium |
| MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded. | ||||
| CVE-2024-3754 | 1 Mnbaa | 1 Alemha Watermark | 2025-07-03 | 4.7 Medium |
| The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2024-33210 | 1 Flatpress | 1 Flatpress | 2025-07-03 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users. | ||||
| CVE-2024-45960 | 1 Tribalsystems | 1 Zenario | 2025-07-03 | 4.8 Medium |
| Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack. | ||||
| CVE-2024-45964 | 1 Tribalsystems | 1 Zenario | 2025-07-03 | 4.8 Medium |
| Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field. | ||||
| CVE-2024-46409 | 1 Seeddms | 1 Seeddms | 2025-07-03 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page. | ||||
| CVE-2024-42901 | 1 Limesurvey | 1 Limesurvey | 2025-07-03 | 4.8 Medium |
| A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file. | ||||
| CVE-2024-44085 | 1 Onlyoffice | 2 Docs, Onlyoffice | 2025-07-03 | 6.1 Medium |
| ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883. | ||||
| CVE-2024-57599 | 1 Douco | 1 Douphp | 2025-07-03 | 4.8 Medium |
| Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php | ||||
| CVE-2024-33297 | 1 Microweber | 1 Microweber | 2025-07-03 | 4.7 Medium |
| Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function | ||||
| CVE-2024-33298 | 1 Microweber | 1 Microweber | 2025-07-03 | 6.1 Medium |
| Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup | ||||
| CVE-2024-33299 | 1 Microweber | 1 Microweber | 2025-07-03 | 4.7 Medium |
| Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users | ||||
| CVE-2024-53620 | 1 Spip | 1 Spip | 2025-07-03 | 4.8 Medium |
| A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter. | ||||
| CVE-2024-55239 | 1 Portabilis | 1 I-educar | 2025-07-03 | 5.4 Medium |
| A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter. | ||||
| CVE-2025-4955 | 1 Amauri | 1 Tarteaucitron.io | 2025-07-02 | 4.7 Medium |
| The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. | ||||
| CVE-2025-45661 | 1 Heavenspell | 1 Minitcg | 2025-07-02 | 5.9 Medium |
| A cross-site scripting (XSS) vulnerability in miniTCG v1.3.1 beta allows attackers to execute abritrary web scripts or HTML via injecting a crafted payload into the id parameter at /members/edit.php. | ||||
ReportizFlow