5.1

CVSS4.0

CVE-2024-58321 - Kentico Xperience <= 13.0.159 Form Validation Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

6.9

CVSS4.0

CVE-2024-58320 - Kentico Xperience <= 13.0.159 Authentication Information Disclosure

An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal netwo…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2024-58319 - Kentico Xperience <= 13.0.160 Pages Dashboard Widget Reflected XSS

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrative users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2024-58318 - Kentico Xperience <= 13.0.162 Rich Text Editor Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in user…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

6.9

CVSS4.0

CVE-2024-58317 - Kentico Xperience <= 13.0.164 Cookie Security Configuration

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session s…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

7.1

CVSS4.0

CVE-2023-53944 - EasyPHP Webserver 14.1 Path Traversal via Directory Traversal Sequences

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

6.9

CVSS4.0

CVE-2023-53943 - GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint

GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify …

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

9.4

CVSS4.0

CVE-2023-53942 - File Thingie 2.5.7 Authenticated Arbitrary File Upload Remote Code Execution

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a …

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

9.3

CVSS4.0

CVE-2023-53941 - EasyPHP Webserver 14.1 Remote Code Execution

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_s…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2023-53939 - TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected galle…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.
Total resulsts: 323511
Page 19 of 32,352
Β« previous page Β» next page
Filters