5.3

CVSS4.0

CVE-2025-14889 - Campcodes Advanced Voting Management System Password voters_edit.php improper authorization

A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler. Performing manipulation of the argument ID results in improper authorization. The attack is possi…

πŸ“… Published: Dec. 18, 2025, 8:02 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 8:02 p.m.

8.4

CVSS4.0

CVE-2023-53940 - Codigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown File

Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file…

πŸ“… Published: Dec. 18, 2025, 7:57 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:57 p.m.

8.5

CVSS4.0

CVE-2023-53937 - Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application sta…

πŸ“… Published: Dec. 18, 2025, 7:57 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:57 p.m.

5.1

CVSS4.0

CVE-2024-58323 - Kentico Xperience <= 13.0.158 Checkbox Form Component Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2024-58322 - Kentico Xperience <= 13.0.158 Shipping Options Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2024-58321 - Kentico Xperience <= 13.0.159 Form Validation Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

6.9

CVSS4.0

CVE-2024-58320 - Kentico Xperience <= 13.0.159 Authentication Information Disclosure

An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal netwo…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2024-58319 - Kentico Xperience <= 13.0.160 Pages Dashboard Widget Reflected XSS

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrative users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2024-58318 - Kentico Xperience <= 13.0.162 Rich Text Editor Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in user…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

6.9

CVSS4.0

CVE-2024-58317 - Kentico Xperience <= 13.0.164 Cookie Security Configuration

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session s…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.
Total resulsts: 323496
Page 17 of 32,350
Β« previous page Β» next page
Filters