Show filters
45 Total Results
Displaying 11-20 of 45
Sort by:
Attacker Value
Unknown

CVE-2014-125108

Disclosure Date: December 23, 2023 (last updated January 04, 2024)
A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The identifier of the patch is d6c21fd8187c5db2a50425ff80694149e75d722e. It is recommended to apply a patch to fix this issue. The identifier VDB-248849 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-47521

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond, AndreSC Q2W3 Post Order allows Reflected XSS.This issue affects Q2W3 Post Order: from n/a through 1.2.8.
Attacker Value
Unknown

CVE-2023-30300

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.
Attacker Value
Unknown

CVE-2021-4296

Disclosure Date: December 29, 2022 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in w3c Unicorn. This issue affects the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 51f75c31f7fc33859a9a571311c67ae4e95d9c68. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217019.
Attacker Value
Unknown

CVE-2021-36896

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2
Attacker Value
Unknown

CVE-2020-4070

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
Attacker Value
Unknown

CVE-2019-15525

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
0
Attacker Value
Unknown

CVE-2017-18497

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The liveforms plugin before 3.4.0 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2015-9301

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
0
Attacker Value
Unknown

EpubCheck 4.0.1 is vulnerable to external XML entity processing attacks

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit this behavior to read arbitrary files, or have the victim execute arbitrary requests on his behalf, abusing the victim's trust relationship with other entities.