Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown

CVE-2025-23754

Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ulrich Sossou The Loops allows Reflected XSS. This issue affects The Loops: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2024-40745

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
0
Attacker Value
Unknown

CVE-2024-40744

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
0
Attacker Value
Unknown

CVE-2024-1817

Disclosure Date: February 23, 2024 (last updated December 18, 2024)
A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254605 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-34022

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rakib Hasan Dynamic QR Code Generator plugin <= 0.0.5 versions.
Attacker Value
Unknown

CVE-2023-37272

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler (JS1). The vulnerability does not affect branch 2.x of JobScheduler (JS7) for releases after 2.1.0. The vulnerability is resolved with release 1.13.19.
Attacker Value
Unknown

CVE-2023-0578

Disclosure Date: March 03, 2023 (last updated November 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies Book Cites allows Cross-Site Scripting (XSS).This issue affects Book Cites: before 23.01.05.
Attacker Value
Unknown

CVE-2023-0577

Disclosure Date: March 03, 2023 (last updated November 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies SOBIAD allows Cross-Site Scripting (XSS).This issue affects SOBIAD: before 23.02.01.
Attacker Value
Unknown

CVE-2022-2806

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
Attacker Value
Unknown

CVE-2020-12712

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.