Total
47486 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-41423 | 1 Terryl | 1 Wp Githuber Md | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in WP Githuber MD plugin v.1.16.2 allows a remote attacker to execute arbitrary code via a crafted payload to the new article function. | |||||
| CVE-2023-41343 | 1 Ragic | 1 Enterprise Cloud Database | 2026-06-17 | N/A | 5.4 MEDIUM |
| Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack. | |||||
| CVE-2023-41318 | 1 Turt2live | 1 Matrix-media-repo | 2026-06-17 | N/A | 4.1 MEDIUM |
| matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inline` upon download. This vulnerability could be leveraged to execute scripts embedded in SVG content. Commits `77ec235` and `bf8abdd` fix the issue and are included in the 1.3.0 release. Operators should upgrade to v1.3.0 as soon as possible. Operators unable to upgrade should override the `Content-Disposition` header returned by matrix-media-repo as a workaround. | |||||
| CVE-2023-41316 | 1 Tolgee | 1 Tolgee | 2026-06-17 | N/A | 5.5 MEDIUM |
| Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML ends up in invitation emails which appear as legitimate org invitations. Bad actors may direct users to malicious website or execute javascript in the context of the users browser. This vulnerability has been addressed in version 3.29.2. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-41250 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 3.5 LOW |
| In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | |||||
| CVE-2023-41249 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | |||||
| CVE-2023-41248 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration | |||||
| CVE-2023-41242 | 1 Creativehassan | 1 Snap Pixel | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions. | |||||
| CVE-2023-41241 | 1 Surecart | 1 Surecart | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions. | |||||
| CVE-2023-41238 | 1 Ultimatelysocial | 1 Social Media Share Buttons \& Social Sharing Icons | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions. | |||||
| CVE-2023-41237 | 1 Everestthemes | 1 Arya Multipurpose Theme | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose Pro theme <= 1.0.8 versions. | |||||
| CVE-2023-41236 | 1 Wedevs | 1 Happy Addons For Elementor | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin <= 2.8.0 versions. | |||||
| CVE-2023-41235 | 1 Everestthemes | 1 Everest News | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Everest News Pro theme <= 1.1.7 versions. | |||||
| CVE-2023-41233 | 1 Welcart | 1 Welcart E-commerce | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script. | |||||
| CVE-2023-41178 | 1 Trendmicro | 1 Mobile Security | 2026-06-17 | N/A | 6.1 MEDIUM |
| Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41176. | |||||
| CVE-2023-41177 | 1 Trendmicro | 1 Mobile Security | 2026-06-17 | N/A | 6.1 MEDIUM |
| Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41178. | |||||
| CVE-2023-41176 | 1 Trendmicro | 1 Mobile Security | 2026-06-17 | N/A | 6.1 MEDIUM |
| Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41177. | |||||
| CVE-2023-41172 | 1 Netscout | 1 Ngeniusone | 2026-06-17 | N/A | 5.4 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). | |||||
| CVE-2023-41171 | 1 Netscout | 1 Ngeniusone | 2026-06-17 | N/A | 5.4 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). | |||||
| CVE-2023-41170 | 1 Netscout | 1 Ngeniusone | 2026-06-17 | N/A | 6.1 MEDIUM |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. | |||||
