Medium · CVSS 6.1
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
Published Oct 18, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
Published Oct 18, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
Published Oct 18, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
Published Oct 18, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
Published Oct 18, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
Published Oct 18, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
devhub 0.102.0 was discovered to contain a broken session control.
Published Oct 17, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.
Published Jan 20, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable.
Published Oct 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.
Published Mar 27, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.1
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
Published Nov 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter.
Published Dec 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.
Published Nov 2, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.
Published Nov 1, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).
Published Oct 31, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.
Published Oct 31, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
Published Oct 11, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.8
Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.
Published Dec 19, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
Published Dec 19, 2022 · Updated Jul 9, 2026
High · CVSS 8.8
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.
Published Sep 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.
Published Oct 3, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
Published Oct 17, 2022 · Updated Jul 9, 2026
High · CVSS 7.2
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
Published Sep 29, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
Published Oct 11, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.8
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.8
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullName parameter.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newTask.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
Published Dec 23, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.3
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
Published Oct 13, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
Published Oct 19, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
Published Sep 20, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
Published Sep 13, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.
Published Sep 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
Published Sep 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
Published Sep 9, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
Published Dec 8, 2022 · Updated Jul 9, 2026
High · CVSS 7.8
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folder on the connected Sage 300 server to view and/or modify the credentials associated with Sage 300 users and SQL accounts to impersonate users and/or access the SQL database as a system administrator. With system administrator-level access to the Sage 300 MS SQL database it would be possible to create, update, and delete all records associated with the program and, depending on the configuration, execute code on the underlying database server.
Published Apr 28, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
Published Oct 24, 2022 · Updated Jul 9, 2026
High · CVSS 8.8
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
Published Aug 28, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
Published Sep 26, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
Published Sep 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).
Published Oct 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.
Published Sep 16, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.3
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.
Published Nov 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
Published Nov 22, 2022 · Updated Jul 9, 2026