• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-24314

February 26, 2023 by

Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the “t” GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

CVE-2020-24316

February 26, 2023 by

WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the “role” GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

CVE-2020-24353

February 26, 2023 by

Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

CVE-2020-24188

February 26, 2023 by

Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 20.03 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2020-24194

February 26, 2023 by

A Cross-site scripting (XSS) vulnerability in ‘user-profile.php’ in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the ‘fullname’ parameter.

CVE-2020-24198

February 26, 2023 by

A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the ‘Brand Name.’

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 769
  • Go to page 770
  • Go to page 771
  • Go to page 772
  • Go to page 773
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE