Export limit exceeded: 46652 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46652 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-32128 | 1 74cms | 1 74cmsse | 2024-11-21 | 6.1 Medium |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im. | ||||
| CVE-2022-32127 | 1 74cms | 1 74cmsse | 2024-11-21 | 6.1 Medium |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total. | ||||
| CVE-2022-32126 | 1 74cms | 1 74cmsse | 2024-11-21 | 6.1 Medium |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company. | ||||
| CVE-2022-32125 | 1 74cms | 1 74cmsse | 2024-11-21 | 6.1 Medium |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job. | ||||
| CVE-2022-32124 | 1 74cms | 1 74cmsse | 2024-11-21 | 6.1 Medium |
| 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/. | ||||
| CVE-2022-32118 | 1 Arox | 1 School Erp Pro | 2024-11-21 | 6.1 Medium |
| Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php. | ||||
| CVE-2022-32115 | 1 Withknown | 1 Known | 2024-11-21 | 6.1 Medium |
| An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file. | ||||
| CVE-2022-32074 | 1 Osticket | 1 Osticket | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file. | ||||
| CVE-2022-32065 | 1 Ruoyi | 1 Ruoyi | 2024-11-21 | 5.4 Medium |
| An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file. | ||||
| CVE-2022-32061 | 1 Snipeitapp | 1 Snipe-it | 2024-11-21 | 4.8 Medium |
| An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file. | ||||
| CVE-2022-32060 | 1 Snipeitapp | 1 Snipe-it | 2024-11-21 | 4.8 Medium |
| An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file. | ||||
| CVE-2022-31914 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 5.4 Medium |
| Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24. | ||||
| CVE-2022-31910 | 1 Online Tutor Portal Site Project | 1 Online Tutor Portal Site | 2024-11-21 | 4.8 Medium |
| Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php. | ||||
| CVE-2022-31906 | 1 Online Fire Reporting System Project | 1 Online Fire Reporting System | 2024-11-21 | 4.8 Medium |
| Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php. | ||||
| CVE-2022-31904 | 1 Uberrider | 1 Mediacenter | 2024-11-21 | 6.1 Medium |
| EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php. | ||||
| CVE-2022-31897 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 6.1 Medium |
| SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=. | ||||
| CVE-2022-31875 | 1 Trendnet | 2 Tv-ip110wn, Tv-ip110wn Firmware | 2024-11-21 | 6.1 Medium |
| Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi | ||||
| CVE-2022-31873 | 1 Trendnet | 2 Tv-ip110wn, Tv-ip110wn Firmware | 2024-11-21 | 6.1 Medium |
| Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi. | ||||
| CVE-2022-31861 | 1 Thingsboard | 1 Thingsboard | 2024-11-21 | 5.4 Medium |
| Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs. | ||||
| CVE-2022-31792 | 1 Watchguard | 1 Fireware | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted requests to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4. | ||||