Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-43111 Cross-site Scripting vulnerability in Mozilla Firefox
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
network
low complexity
mozilla CWE-79
6.1
2024-08-06 CVE-2024-43112 Cross-site Scripting vulnerability in Mozilla Firefox
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
network
low complexity
mozilla CWE-79
6.1
2024-08-06 CVE-2024-43113 Cross-site Scripting vulnerability in Mozilla Firefox
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
network
low complexity
mozilla CWE-79
6.1
2024-08-06 CVE-2023-40819 Cross-site Scripting vulnerability in Devlop.Systems Id4Portais
ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.
network
low complexity
devlop-systems CWE-79
6.1
2024-08-06 CVE-2024-40101 Cross-site Scripting vulnerability in Microweber
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
network
low complexity
microweber CWE-79
6.1
2024-08-06 CVE-2024-41910 Cross-site Scripting vulnerability in HP Poly Clariti Manager Firmware
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices.
network
low complexity
hp CWE-79
6.1
2024-08-06 CVE-2024-41911 Cross-site Scripting vulnerability in HP Poly Clariti Manager Firmware
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices.
network
low complexity
hp CWE-79
5.4
2024-08-06 CVE-2024-33982 Cross-site Scripting vulnerability in Janobe products
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0.
network
low complexity
janobe CWE-79
6.1
2024-08-06 CVE-2024-33983 Cross-site Scripting vulnerability in Janobe products
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0.
network
low complexity
janobe CWE-79
6.1
2024-08-06 CVE-2024-33984 Cross-site Scripting vulnerability in Janobe products
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0.
network
low complexity
janobe CWE-79
6.1