Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

559 CVEs tagged with CWE-8016 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2024-20362

Published Apr 3, 2024

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2024-31062

Published Mar 28, 2024

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28108

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possibl…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1606

Published Mar 18, 2024

Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lea…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26282

Published Feb 22, 2024

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25873

Published Feb 22, 2024

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26482

Published Feb 22, 2024

An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formattin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24812

Published Feb 7, 2024

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24807

Published Feb 5, 2024

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-24574

Published Feb 5, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50933

Published Feb 2, 2024

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24571

Published Jan 31, 2024

facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23841

Published Jan 30, 2024

apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vul…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5933

Published Jan 26, 2024

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user n…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23817

Published Jan 25, 2024

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page o…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0183

Published Jan 1, 2024

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/students.php of the…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-46722

Published Oct 31, 2023

The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gai…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46235

Published Oct 31, 2023

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a lack of request sanitization in the logs, a malicious requ…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5582

Published Oct 14, 2023

A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown processing of the component Personal Profile Page. The manipu…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36555

Published Oct 10, 2023

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-44393

Published Oct 9, 2023

Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&i…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 351-375 of 559 CVEsPage 15 of 23