Total
47486 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-42427 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is using the product. | |||||
| CVE-2023-42371 | 1 Summernote | 1 Rich Text Editor | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component. | |||||
| CVE-2023-42362 | 1 Teller | 1 Teller | 2026-06-17 | N/A | 5.4 MEDIUM |
| An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands and obtain sensitive information via uploading a crafted file. | |||||
| CVE-2023-42345 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. | |||||
| CVE-2023-42343 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. | |||||
| CVE-2023-42327 | 1 Netgate | 1 Pfsense | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page. | |||||
| CVE-2023-42325 | 1 Netgate | 1 Pfsense | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page. | |||||
| CVE-2023-42308 | 1 Code-projects | 1 Exam Form Submission | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" and "Subject Code" Section. | |||||
| CVE-2023-42307 | 1 Code-projects | 1 Exam Form Submission | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section. | |||||
| CVE-2023-42253 | 1 Vehicle Management Project | 1 Vehicle Management | 2026-06-17 | N/A | 6.1 MEDIUM |
| Code-Projects Vehicle Management 1.0 is vulnerable to Cross Site Scripting (XSS) in Add Accounts via Invoice No, To, and Mammul. | |||||
| CVE-2023-42250 | 1 Seling | 1 Visual Access Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php. | |||||
| CVE-2023-42249 | 1 Seling | 1 Visual Access Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php. | |||||
| CVE-2023-42247 | 1 Seling | 1 Visual Access Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php. | |||||
| CVE-2023-42246 | 1 Seling | 1 Visual Access Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php. | |||||
| CVE-2023-42245 | 1 Seling | 1 Visual Access Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php. | |||||
| CVE-2023-42233 | 1 Zucchetti | 1 Helpdeskadvanced | 2026-06-17 | N/A | 6.1 MEDIUM |
| Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function. | |||||
| CVE-2023-42230 | 1 Zucchetti | 1 Helpdeskadvanced | 2026-06-17 | N/A | 6.1 MEDIUM |
| Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function. | |||||
| CVE-2023-42034 | 1 Visualware | 1 Myconnection Server | 2026-06-17 | N/A | 8.8 HIGH |
| Visualware MyConnection Server doRTAAccessCTConfig Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Visualware MyConnection Server. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the doRTAAccessCTConfig method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21613. | |||||
| CVE-2023-42029 | 4 Hp, Ibm, Linux and 1 more | 6 Hp-ux, Aix, Cics Tx and 3 more | 2026-06-17 | N/A | 4.8 MEDIUM |
| IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 266059. | |||||
| CVE-2023-42022 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2026-06-17 | N/A | 5.4 MEDIUM |
| IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 265938. | |||||
