Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2021-43505

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

CVE
#xss#vulnerability#web#windows#apple#linux#js#java
CVE-2022-0350: :arrow_up: · Vanessa219/vditor@e912e36

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

CVE-2022-0350: :arrow_up: · Vanessa219/vditor@e912e36

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

CVE-2022-24299

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

CVE-2021-43661: iot-vuls/xss-vulnerability.md at main · chibataiki/iot-vuls

totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.

CVE-2022-26645: CVE/CVE-2022-26645 at main · erik-451/CVE

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

CVE-2022-26644: CVE/CVE-2022-26644 at main · erik-451/CVE

Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

CVE-2022-24135: Search function Cross Site Script(XSS) Vulnerability · Issue #17 · 78778443/QingScan

QingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions.

CVE-2022-28223: Post auth RCE based in malicious LUA plugin script upload SCADA controllers located in Russia

Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

CVE-2021-44310

An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.