Export limit exceeded: 49147 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49147 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-27104 | 1 Glpi-project | 1 Glpi | 2025-01-02 | 4.5 Medium |
| GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13. | ||||
| CVE-2024-27914 | 1 Glpi-project | 1 Glpi | 2025-01-02 | 5.3 Medium |
| GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13. | ||||
| CVE-2024-1474 | 1 Progress | 1 Ws Ftp Server | 2025-01-02 | 7.5 High |
| In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface. | ||||
| CVE-2023-35621 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 7.5 High |
| Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | ||||
| CVE-2023-36020 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 7.6 High |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||||
| CVE-2023-29345 | 1 Microsoft | 1 Edge Chromium | 2025-01-01 | 6.1 Medium |
| Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||||
| CVE-2023-29347 | 1 Microsoft | 1 Windows Admin Center | 2025-01-01 | 8.7 High |
| Windows Admin Center Spoofing Vulnerability | ||||
| CVE-2023-21565 | 1 Microsoft | 1 Azure Devops Server | 2025-01-01 | 7.1 High |
| Azure DevOps Server Spoofing Vulnerability | ||||
| CVE-2023-24896 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 5.4 Medium |
| Dynamics 365 Finance Spoofing Vulnerability | ||||
| CVE-2023-23383 | 1 Microsoft | 1 Azure Service Fabric | 2025-01-01 | 8.2 High |
| Service Fabric Explorer Spoofing Vulnerability | ||||
| CVE-2023-21564 | 1 Microsoft | 1 Azure Devops Server | 2025-01-01 | 7.1 High |
| Azure DevOps Server Cross-Site Scripting Vulnerability | ||||
| CVE-2023-21573 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 5.4 Medium |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||||
| CVE-2023-21572 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 6.5 Medium |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||||
| CVE-2023-21571 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 5.4 Medium |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||||
| CVE-2023-21570 | 1 Microsoft | 1 Dynamics 365 | 2025-01-01 | 5.4 Medium |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||||
| CVE-2023-21806 | 1 Microsoft | 1 Power Bi Report Server | 2025-01-01 | 8.2 High |
| Power BI Report Server Spoofing Vulnerability | ||||
| CVE-2024-43476 | 1 Microsoft | 1 Dynamics 365 | 2024-12-31 | 7.6 High |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||||
| CVE-2024-38221 | 1 Microsoft | 1 Edge Chromium | 2024-12-31 | 4.3 Medium |
| Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||||
| CVE-2023-35146 | 1 Jenkins | 1 Template Workflows | 2024-12-31 | 5.4 Medium |
| Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs. | ||||
| CVE-2024-2071 | 1 Remyandrade | 1 Faq Management System | 2024-12-31 | 3.5 Low |
| A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affected by this issue is some unknown functionality of the component Update FAQ. The manipulation of the argument Frequently Asked Question leads to cross site scripting. The attack may be launched remotely. VDB-255386 is the identifier assigned to this vulnerability. | ||||