Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-43884: GitHub - dpuenteramirez/XSS-ReferenceID-Subrion_4.2.1

A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter.

CVE
#xss#vulnerability#web#git
CVE-2023-43876: October-CMS-Reflected-XSS---Installation/README.md at main · sromanhu/October-CMS-Reflected-XSS---Installation

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

CVE-2023-42756: cve-details

A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.

CVE-2023-40307: Privileges Memory Corruption (Out-of-bound write)

An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the application unavailable and allow reading or modification of data.

CVE-2023-43874: e107-CMS-Stored-XSS---MetaCustomTags/README.md at main · sromanhu/e107-CMS-Stored-XSS---MetaCustomTags

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.

CVE-2023-43873: e107-CMS-Stored-XSS---Manage/README.md at main · sromanhu/e107-CMS-Stored-XSS---Manage

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

CVE-2023-43871: WBCE-Arbitrary-File-Upload--XSS---Media/README.md at main · sromanhu/WBCE-Arbitrary-File-Upload--XSS---Media

A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-5215: cve-details

A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the nbd_get_size() function correctly.

CVE-2023-44276: Advisory X41-2023-001: Two Vulnerabilities in OPNsense

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.