Show filters
141 Total Results
Displaying 71-80 of 141
Sort by:
Attacker Value
Unknown

CVE-2022-0989

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
Attacker Value
Unknown

CVE-2022-28648

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
Attacker Value
Unknown

CVE-2022-25620

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.
Attacker Value
Unknown

CVE-2008-10001

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2003-5003

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipulation with an unknown input leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2022-1002

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
Attacker Value
Unknown

CVE-2022-24749

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or loaded outside of the IMG tag. The problem applies both to the files opened on the admin panel and shop pages. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. As a workaround, require a library that adds on-upload file sanitization and overwrite the service before writing the file to the filesystem. The GitHub Security Advisory contains more specific information about the workaround.
Attacker Value
Unknown

CVE-2022-21145

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-36777

Disclosure Date: February 23, 2022 (last updated February 23, 2025)
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.
Attacker Value
Unknown

CVE-2022-0519

Disclosure Date: February 08, 2022 (last updated February 23, 2025)
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.