• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-28457

February 26, 2023 by

This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.

CVE-2020-28459

February 26, 2023 by

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

CVE-2020-28470

February 26, 2023 by

This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

CVE-2020-28408

February 26, 2023 by

The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.

CVE-2020-28409

February 26, 2023 by

The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.

CVE-2020-28414

February 26, 2023 by

A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28415).

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 719
  • Go to page 720
  • Go to page 721
  • Go to page 722
  • Go to page 723
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE