• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2021-37393

February 23, 2023 by

In RPCMS v1.8 and below, the “nickname” variable is not properly sanitized before being displayed on page. Attacker can use “update password” function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.

CVE-2021-37402

February 23, 2023 by

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

CVE-2021-37403

February 23, 2023 by

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.

CVE-2021-37412

February 23, 2023 by

The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.

CVE-2021-37416

February 23, 2023 by

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

CVE-2021-37267

February 23, 2023 by

Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1395
  • Go to page 1396
  • Go to page 1397
  • Go to page 1398
  • Go to page 1399
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE