• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2021-30134

February 23, 2023 by

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

CVE-2021-3014

February 23, 2023 by

In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.

CVE-2021-30140

February 23, 2023 by

LiquidFiles 3.4.15 has stored XSS through the “send email” functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.

CVE-2021-30146

February 23, 2023 by

Seafile 7.0.5 (2019) allows Persistent XSS via the “share of library functionality.”

CVE-2021-30150

February 23, 2023 by

Composr 10.0.36 allows XSS in an XML script.

CVE-2021-30151

February 23, 2023 by

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1475
  • Go to page 1476
  • Go to page 1477
  • Go to page 1478
  • Go to page 1479
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE