Total
45382 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-27666 | 1 Auto Dealer Management System Project | 1 Auto Dealer Management System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Auto Dealer Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the name parameter at /classes/SystemSettings.php?f=update_settings. | |||||
| CVE-2023-27237 | 1 Lavalite | 1 Lavalite | 2026-07-09 | N/A | 6.1 MEDIUM |
| LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. | |||||
| CVE-2023-27000 | 1 Netscout | 1 Ngeniusone | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s). | |||||
| CVE-2023-26998 | 1 Netscout | 1 Ngeniusone | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page. | |||||
| CVE-2023-26961 | 1 Alteryx | 1 Alteryx Server | 2026-07-09 | N/A | 4.8 MEDIUM |
| Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request. | |||||
| CVE-2023-25309 | 1 Fetlife | 1 Rollout-ui | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality. | |||||
| CVE-2023-25292 | 1 Group-office | 1 Group Office | 2026-07-09 | N/A | 6.1 MEDIUM |
| Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie. | |||||
| CVE-2023-24721 | 1 Liveaction | 1 Livesp | 2026-07-09 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML. | |||||
| CVE-2023-24282 | 1 Poly | 2 Trio 8800, Trio 8800 Firmware | 2026-07-09 | N/A | 5.4 MEDIUM |
| An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file. | |||||
| CVE-2023-23326 | 1 Avantfax | 1 Avantfax | 2026-07-09 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session. | |||||
| CVE-2023-22985 | 1 Simple Guestbook Management System Project | 1 Simple Guestbook Management System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments. | |||||
| CVE-2022-48111 | 1 Siri-informatica | 1 Wi400 | 2026-07-09 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter. | |||||
| CVE-2022-48085 | 1 Softr | 1 Softr | 2026-07-09 | N/A | 5.4 MEDIUM |
| Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. | |||||
| CVE-2022-44962 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field. | |||||
| CVE-2022-44961 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |||||
| CVE-2022-44960 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field. | |||||
| CVE-2022-44959 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |||||
| CVE-2022-44957 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |||||
| CVE-2022-44956 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |||||
| CVE-2022-44955 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 5.4 MEDIUM |
| webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field. | |||||
