Search Results (49651 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-0897 1 Fastlinemedia 1 Beaver Builder 2025-01-02 6.4 Medium
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 2.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-1038 1 Fastlinemedia 1 Beaver Builder 2025-01-02 5.4 Medium
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via a 'playground.wordpress.net' parameter in all versions up to, and including, 2.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2024-1074 1 Fastlinemedia 1 Beaver Builder 2025-01-02 6.4 Medium
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the audio widget 'link_url' parameter in all versions up to, and including, 2.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-55541 3 Acronis, Linux, Microsoft 3 Cyber Protect, Linux Kernel, Windows 2025-01-02 6.1 Medium
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
CVE-2024-27104 1 Glpi-project 1 Glpi 2025-01-02 4.5 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13.
CVE-2024-27914 1 Glpi-project 1 Glpi 2025-01-02 5.3 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13.
CVE-2024-1474 1 Progress 1 Ws Ftp Server 2025-01-02 7.5 High
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
CVE-2023-35621 1 Microsoft 1 Dynamics 365 2025-01-01 7.5 High
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
CVE-2023-36020 1 Microsoft 1 Dynamics 365 2025-01-01 7.6 High
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-29345 1 Microsoft 1 Edge Chromium 2025-01-01 6.1 Medium
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-36892 1 Microsoft 1 Sharepoint Server 2025-01-01 8 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-29347 1 Microsoft 1 Windows Admin Center 2025-01-01 8.7 High
Windows Admin Center Spoofing Vulnerability
CVE-2023-21565 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Spoofing Vulnerability
CVE-2023-24896 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Dynamics 365 Finance Spoofing Vulnerability
CVE-2023-23383 1 Microsoft 1 Azure Service Fabric 2025-01-01 8.2 High
Service Fabric Explorer Spoofing Vulnerability
CVE-2023-21564 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Cross-Site Scripting Vulnerability
CVE-2023-21573 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21572 1 Microsoft 1 Dynamics 365 2025-01-01 6.5 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21571 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21570 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability