Total
45372 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-35501 | 1 Amasty | 1 Blog Pro | 2026-07-09 | N/A | 5.4 MEDIUM |
| Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function. | |||||
| CVE-2022-35500 | 1 Amasty | 1 Blog Pro | 2026-07-09 | N/A | 5.4 MEDIUM |
| Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality. | |||||
| CVE-2022-35155 | 1 Phpgurukul | 1 Bus Pass Management System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter. | |||||
| CVE-2022-35131 | 1 Joplinapp | 1 Joplin | 2026-07-09 | N/A | 9.0 CRITICAL |
| Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | |||||
| CVE-2022-35118 | 1 Pyrocms | 1 Pyrocms | 2026-07-09 | N/A | 6.1 MEDIUM |
| PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | |||||
| CVE-2022-34611 | 1 Online Fire Reporting System Project | 1 Online Fire Reporting System | 2026-07-09 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field. | |||||
| CVE-2022-33098 | 1 Magnolia-cms | 1 Magnolia Cms | 2026-07-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture. | |||||
| CVE-2022-33075 | 1 Phpgurukul | 1 Zoo Management System | 2026-07-09 | 3.5 LOW | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors. | |||||
| CVE-2022-33009 | 1 Lightcms Project | 1 Lightcms | 2026-07-09 | 3.5 LOW | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file. | |||||
| CVE-2022-31904 | 1 Uberrider | 1 Mediacenter | 2026-07-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php. | |||||
| CVE-2022-31897 | 1 Phpgurukul | 1 Zoo Management System | 2026-07-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=. | |||||
| CVE-2022-31358 | 1 Proxmox | 1 Virtual Environment | 2026-07-09 | N/A | 9.0 CRITICAL |
| A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/. | |||||
| CVE-2022-29649 | 1 Qsmart Next Project | 1 Qsmart Next | 2026-07-09 | N/A | 6.1 MEDIUM |
| Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability. | |||||
| CVE-2022-29005 | 1 Phpgurukul | 1 Online Birth Certificate System | 2026-07-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters. | |||||
| CVE-2022-29004 | 1 Phpgurukul | 1 E-diary Management System | 2026-07-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php. | |||||
| CVE-2022-28982 | 1 Liferay | 2 Dxp, Liferay Portal | 2026-07-09 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag. | |||||
| CVE-2022-28980 | 1 Liferay | 2 Dxp, Liferay Portal | 2026-07-09 | N/A | 6.1 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix. | |||||
| CVE-2022-28979 | 1 Liferay | 3 Digital Experience Platform, Dxp, Liferay Portal | 2026-07-09 | N/A | 6.1 MEDIUM |
| Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Parameter Name text field. | |||||
| CVE-2022-28978 | 1 Liferay | 3 Digital Experience Platform, Dxp, Liferay Portal | 2026-07-09 | N/A | 5.4 MEDIUM |
| Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and Liferay DXP 7.0 before fix pack 102, 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the a user's name. | |||||
| CVE-2022-28975 | 1 Infoblox | 1 Nios | 2026-07-09 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field. | |||||
