Total
37352 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-40355 | 1 Axigen | 1 Axigen Mobile Webmail | 2025-06-17 | 5.4 Medium |
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions. | ||||
CVE-2023-40262 | 1 Unify | 1 Openscape Voice Trace Manager V8 | 2025-06-17 | 6.1 Medium |
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request. | ||||
CVE-2024-34507 | 2 Fedoraproject, Mediawiki | 2 Fedora, Mediawiki | 2025-06-17 | 7.4 High |
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000. | ||||
CVE-2023-52329 | 1 Trendmicro | 1 Apex Central | 2025-06-17 | 6.1 Medium |
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326. | ||||
CVE-2023-52274 | 1 Yzmcms | 1 Yzmcms | 2025-06-17 | 6.1 Medium |
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header. | ||||
CVE-2023-52068 | 1 Kodcloud | 1 Kodbox | 2025-06-17 | 6.1 Medium |
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs. | ||||
CVE-2023-50092 | 1 Apiida | 1 Api Gateway Manager | 2025-06-17 | 6.1 Medium |
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS). | ||||
CVE-2023-49950 | 1 Logpoint | 1 Siem | 2025-06-17 | 5.4 Medium |
The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure. | ||||
CVE-2023-49101 | 1 Axigen | 1 Axigen Mobile Webmail | 2025-06-17 | 6.1 Medium |
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates. | ||||
CVE-2023-48974 | 1 Axigen | 1 Axigen Mail Server | 2025-06-17 | 9.6 Critical |
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter. | ||||
CVE-2023-41619 | 1 Emlog | 1 Emlog | 2025-06-17 | 6.1 Medium |
Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write. | ||||
CVE-2023-6161 | 1 Themeum | 1 Wp Crowdfunding | 2025-06-17 | 6.1 Medium |
The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||||
CVE-2023-36236 | 1 Webkul | 1 Bagisto | 2025-06-17 | 4.8 Medium |
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. | ||||
CVE-2023-25365 | 1 Octobercms | 1 October | 2025-06-17 | 7.8 High |
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3 | ||||
CVE-2023-25295 | 1 Gruen | 1 Evewa3 | 2025-06-17 | 6.1 Medium |
A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel. | ||||
CVE-2024-33791 | 1 Netis-systems | 2 Mex605, Mex605 Firmware | 2025-06-17 | 4.6 Medium |
A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function. | ||||
CVE-2024-34467 | 1 Thinkphp | 1 Thinkphp | 2025-06-17 | 6.1 Medium |
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl. | ||||
CVE-2024-34468 | 1 Rukovoditel | 1 Rukovoditel | 2025-06-17 | 6.1 Medium |
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page. | ||||
CVE-2024-34469 | 1 Rukovoditel | 1 Rukovoditel | 2025-06-17 | 7.1 High |
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. | ||||
CVE-2024-29273 | 1 Dzzoffice | 1 Dzzoffice | 2025-06-17 | 6.1 Medium |
There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document. |