• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2021-27330

February 23, 2023 by

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.

CVE-2021-27332

February 23, 2023 by

Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.

CVE-2021-27338

February 23, 2023 by

Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.

CVE-2021-27214

February 23, 2023 by

A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.

CVE-2021-27222

February 23, 2023 by

In the “Time in Status” app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.

CVE-2021-27237

February 23, 2023 by

The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1519
  • Go to page 1520
  • Go to page 1521
  • Go to page 1522
  • Go to page 1523
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE