Total
47493 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-36970 | 1 Cmsmadesimple | 1 Cms Made Simple | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function. | |||||
| CVE-2023-36942 | 1 Phpgurukul | 1 Online Fire Reporting System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field. | |||||
| CVE-2023-36941 | 1 Phpgurukul | 1 Online Fire Reporting System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields. | |||||
| CVE-2023-36940 | 1 Phpgurukul | 1 Online Fire Reporting System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field. | |||||
| CVE-2023-36939 | 1 Phpgurukul | 1 Hostel Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field. | |||||
| CVE-2023-36936 | 1 Phpgurukul | 1 Online Security Guards Hiring System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box. | |||||
| CVE-2023-36918 | 1 Sap | 1 Enable Now | 2026-06-17 | N/A | 6.1 MEDIUM |
| In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information. | |||||
| CVE-2023-36892 | 1 Microsoft | 1 Sharepoint Server | 2026-06-17 | N/A | 8.0 HIGH |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||
| CVE-2023-36891 | 1 Microsoft | 1 Sharepoint Server | 2026-06-17 | N/A | 8.0 HIGH |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||
| CVE-2023-36886 | 1 Microsoft | 1 Dynamics 365 | 2026-06-17 | N/A | 7.6 HIGH |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2023-36828 | 1 Statamic | 1 Statamic | 2026-06-17 | N/A | 5.5 MEDIUM |
| Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue. | |||||
| CVE-2023-36823 | 2 Debian, Sanitize Project | 2 Debian Linux, Sanitize | 2026-06-17 | N/A | 7.1 HIGH |
| Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. Sanitize 6.0.2 performs additional escaping of CSS in `style` element content, which fixes this issue. Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content. | |||||
| CVE-2023-36816 | 1 2fauth | 1 2fauth | 2026-06-17 | N/A | 6.1 MEDIUM |
| 2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested in docker-compose environment. This vulnerability has been patched in version 4.0.3. | |||||
| CVE-2023-36809 | 1 Kiwitcms | 1 Kiwi Tcms | 2026-06-17 | N/A | 8.1 HIGH |
| Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such files are accessed directly. The previous Nginx configuration was incorrect allowing certain browsers like Firefox to ignore the `Content-Type: text/plain` header on some occasions thus allowing potentially dangerous scripts to be executed. Additionally, file upload validators and parts of the HTML rendering code had been found to require additional sanitation and improvements. Version 12.5 fixes this vulnerability with updated Nginx content type configuration, improved file upload validation code to prevent more potentially dangerous uploads, and Sanitization of test plan names used in the `tree_view_html()` function. | |||||
| CVE-2023-36806 | 1 Contao | 1 Contao | 2026-06-17 | N/A | 6.5 MEDIUM |
| Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users. | |||||
| CVE-2023-36800 | 1 Microsoft | 1 Dynamics 365 | 2026-06-17 | N/A | 7.6 HIGH |
| Dynamics Finance and Operations Cross-site Scripting Vulnerability | |||||
| CVE-2023-36692 | 1 Wp-cirrus Project | 1 Wp-cirrus | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Kramer & Hendrik Thole WP-Cirrus plugin <= 0.6.11 versions. | |||||
| CVE-2023-36689 | 1 Wpfactory | 1 Wpfactory Helper | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions. | |||||
| CVE-2023-36688 | 1 Idoweb | 1 Simple Site Verify | 2026-06-17 | N/A | 4.3 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions. | |||||
| CVE-2023-36686 | 1 Cartflows | 1 Cartflows | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions. | |||||
