Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

561 CVEs tagged with CWE-8018 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2024-32484

Published Jul 22, 2024

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execu…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-35006

Published Jul 10, 2024

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25639

Published Jul 8, 2024

Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27716

Published Jul 5, 2024

Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.

CVSS 5.4 · Medium

CVE-2024-22277

Published Jul 4, 2024

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTM…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6052

Published Jul 3, 2024

Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28832

Published Jun 25, 2024

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbit…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28831

Published Jun 25, 2024

Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37732

Published Jun 24, 2024

Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6251

Published Jun 22, 2024

A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the file /index.php?app=main&inc=feature_phonebook&op=phoneboo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38055

Published Jun 21, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum:…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6183

Published Jun 20, 2024

A vulnerability classified as problematic has been found in EZ-Suite EZ-Partner 5. Affected is an unknown function of the component Forgot Password Handler. The manipulation leads…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6108

Published Jun 18, 2024

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/v…

CVSS 6.9 · Medium

CVE-2024-38469

Published Jun 17, 2024

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5741

Published Jun 17, 2024

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37297

Published Jun 12, 2024

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a l…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5851

Published Jun 11, 2024

A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the file /index.php?app=main&inc=feature_schedule&op=list of th…

CVSS 5.3 · Medium

CVE-2024-37166

Published Jun 10, 2024

ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS…

CVSS 8.9 · High

CVE-2024-35680

Published Jun 10, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37156

Published Jun 6, 2024

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XS…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32464

Published Jun 4, 2024

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain un…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49852

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue af…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-48285

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe P…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-47513

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: f…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Showing 301-325 of 561 CVEsPage 13 of 23