Vulnerabilities (CVE)

Filtered by CWE-79
Total 45382 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-26367 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.
CVE-2024-24397 1 Stimulsoft 1 Dashboards.js 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.
CVE-2024-24396 1 Stimulsoft 1 Dashboard.js 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
CVE-2024-22780 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.
CVE-2023-51946 1 Actidata 2 Actinas Sl 2u-8 Rdx, Actinas Sl 2u-8 Rdx Firmware 2026-07-09 N/A 6.1 MEDIUM
Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.
CVE-2023-50470 1 Seacms 1 Seacms 2026-07-09 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-49494 1 Dedecms 1 Dedecms 2026-07-09 N/A 6.1 MEDIUM
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
CVE-2023-48940 1 Daicuo 1 Daicuo 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-47324 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 5.4 MEDIUM
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
CVE-2023-46952 1 Abocms 1 Abo.cms 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer header.
CVE-2023-46344 1 Solar-log 2 2000 Pm\+, 2000 Pm\+ Firmware 2026-07-09 N/A 5.4 MEDIUM
A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.
CVE-2023-45992 1 Commscope 1 Ruckus Cloudpath Enrollment System 2026-07-09 N/A 9.6 CRITICAL
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
CVE-2023-43232 1 Dedebiz 1 Dedebiz 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.
CVE-2023-42426 1 Froala 1 Froala Editor 2026-07-09 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.
CVE-2023-42399 1 Xdsoft 1 Joditeditor 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.
CVE-2023-41453 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.
CVE-2023-41451 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
CVE-2023-41448 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.
CVE-2023-41447 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.
CVE-2023-41446 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.