Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-23161: CVE/CVE-2023-23161.txt at main · rahulpatwari/CVE

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.

CVE
#sql#xss#vulnerability#web#windows#apple#php#chrome#webkit
CVE-2022-44261: AveryDennison/AveryDennison_MonarchM9855_XSS at main · IthacaLabs/AveryDennison

Avery Dennison Monarch Printer M9855 is vulnerable to Cross Site Scripting (XSS).

Malicious Game Mods Target Dota 2 Game Users

Valve's unpatched JavaScript engine and incomplete modification vetting process for Steam-delivered mods led to user systems being backdoored.

CVE-2023-24234: GitHub - stemword/php-inventory-management-system: Open source inventory management system with php and mysql Invoice generation and easy to download invoice in PDF format Lightweight and easy to use

A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.

CVE-2023-24230: Release Formwork 1.12.1 · getformwork/formwork

A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page title parameter.

Red Hat Security Advisory 2023-0708-01

Red Hat Security Advisory 2023-0708-01 - Red Hat OpenShift Serverless Client kn 1.27.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.27.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms.

ChiKoi 1.0 Cross Site Scripting

ChiKoi version 1.0 suffers from a cross site scripting vulnerability.

Radio silence from DMS vendor quartet over XSS zero-days

No response or patch yet forthcoming from providers of vulnerable document management systems