Search Results (42958 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-45552 1 Veridiumid 1 Veridiumad 2025-04-16 6.5 Medium
In VeridiumID before 3.5.0, a stored cross-site scripting (XSS) vulnerability has been discovered in the admin portal that allows an authenticated attacker to take over all accounts by sending malicious input via the self-service portal.
CVE-2024-34224 2 Oretnom23, Sourcecodester 2 Computer Laboratory Management System, Computer Laboratory Management System 2025-04-16 7.3 High
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVE-2024-29865 1 Logpoint 1 Siem 2025-04-16 5.4 Medium
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2023-49983 1 Oretnom23 1 School Fees Management System 2025-04-16 6.8 Medium
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2023-49986 1 Oretnom23 1 School Fees Management System 2025-04-16 4.7 Medium
A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2024-25551 1 Oretnom23 1 Simple Student Attendance System 2025-04-16 6.1 Medium
Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.
CVE-2024-25434 1 Pkp.sfu 1 Open Journal Systems 2025-04-16 5.4 Medium
A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.
CVE-2023-49985 1 Oretnom23 1 School Fees Management System 2025-04-16 6.5 Medium
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.
CVE-2023-49984 1 Oretnom23 1 School Fees Management System 2025-04-16 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2022-46096 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2025-04-16 6.1 Medium
A Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows attackers to execute arbitrary code via the txtfullname parameter or txtphone parameter to register.php without logging in.
CVE-2022-46095 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2025-04-16 6.1 Medium
Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via verification.php because the program does not verify the txtvaccinationID parameter.
CVE-2022-44449 1 Zenphoto 1 Zenphoto 2025-04-16 6.1 Medium
Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
CVE-2022-40841 1 Ndk-design 1 Ndkadvancedcustomizationfields 2025-04-16 6.1 Medium
A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter.
CVE-2022-36222 1 Nokia 2 Fastmile, Fastmile Firmware 2025-04-16 8.4 High
Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.
CVE-2021-27430 1 Ge 1 Ur Bootloader Binary 2025-04-16 8.4 High
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
CVE-2020-25163 1 Osisoft 1 Pi Vision 2025-04-16 7.7 High
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.
CVE-2021-43932 1 Smartptt 1 Smartptt Scada 2025-04-16 9 Critical
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
CVE-2021-33014 1 Kuka 3 Kr C4, Kr C4 Firmware, Kss 2025-04-16 8.8 High
An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.
CVE-2022-2140 1 Smartics 1 Smartics 2025-04-16 8.8 High
Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.
CVE-2022-2199 1 Micodus 2 Mv720, Mv720 Firmware 2025-04-16 7.5 High
The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request.