Total
47493 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-33208 | 1 Cookie Monster Project | 1 Cookie Monster | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gsmith Cookie Monster plugin <= 1.51 versions. | |||||
| CVE-2023-33197 | 1 Craftcms | 1 Craft Cms | 2026-06-17 | N/A | 5.5 MEDIUM |
| Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6. | |||||
| CVE-2023-33196 | 1 Craftcms | 1 Craft Cms | 2026-06-17 | N/A | 5.5 MEDIUM |
| Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7. | |||||
| CVE-2023-33195 | 1 Craftcms | 1 Craft Cms | 2026-06-17 | N/A | 5.0 MEDIUM |
| Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6. | |||||
| CVE-2023-33194 | 2 Craftcms, Craftercms | 2 Craft Cms, Craftercms | 2026-06-17 | N/A | 3.7 LOW |
| Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6. | |||||
| CVE-2023-33186 | 1 Zulip | 1 Zulip Server | 2026-06-17 | N/A | 8.2 HIGH |
| Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and 7.0-beta2, is vulnerable to a cross-site scripting vulnerability in tooltips on the message feed. An attacker who can send messages could maliciously craft a topic for the message, such that a victim who hovers the tooltip for that topic in their message feed triggers execution of JavaScript code controlled by the attacker. | |||||
| CVE-2023-33171 | 1 Microsoft | 1 Dynamics 365 | 2026-06-17 | N/A | 8.2 HIGH |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2023-33159 | 1 Microsoft | 1 Sharepoint Server | 2026-06-17 | N/A | 8.8 HIGH |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||
| CVE-2023-33132 | 1 Microsoft | 1 Sharepoint Server | 2026-06-17 | N/A | 6.3 MEDIUM |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||
| CVE-2023-33130 | 1 Microsoft | 1 Sharepoint Server | 2026-06-17 | N/A | 7.3 HIGH |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||
| CVE-2023-33007 | 1 Jenkins | 1 Loadcomplete Support | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |||||
| CVE-2023-33002 | 1 Jenkins | 1 Testcomplete Support | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |||||
| CVE-2023-32984 | 1 Jenkins | 1 Testng Results | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on the plugin's test information pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a crafted TestNG report file. | |||||
| CVE-2023-32977 | 1 Jenkins | 1 Pipeline\ | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately. | |||||
| CVE-2023-32969 | 1 Qnap | 3 Qts, Quts Hero, Qutscloud | 2026-06-17 | N/A | 4.9 MEDIUM |
| A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later | |||||
| CVE-2023-32965 | 1 Crudlab | 1 Jazz Popups | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions. | |||||
| CVE-2023-32962 | 1 Hasthemes | 1 Wishsuite | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions. | |||||
| CVE-2023-32961 | 1 Zotpress Project | 1 Zotpress | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions. | |||||
| CVE-2023-32958 | 1 Nosegraze | 1 Novelist | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions. | |||||
| CVE-2023-32957 | 1 Dazzlersoft | 1 Team Members Showcase | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 versions. | |||||
