Total
47493 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-31934 | 1 Phpgurukul | 1 Rail Pass Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php. | |||||
| CVE-2023-31928 | 1 Broadcom | 1 Brocade Fabric Operating System | 2026-06-17 | N/A | 6.3 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application. | |||||
| CVE-2023-31862 | 1 Jizhicms | 1 Jizhicms | 2026-06-17 | N/A | 5.4 MEDIUM |
| jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package. | |||||
| CVE-2023-31860 | 1 Wuzhicms | 1 Wuzhicms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. | |||||
| CVE-2023-31853 | 1 Cudy | 2 Lt400, Lt400 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter. | |||||
| CVE-2023-31852 | 1 Cudy | 2 Lt400, Lt400 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter. | |||||
| CVE-2023-31851 | 1 Cudy | 2 Lt400, Lt400 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter. | |||||
| CVE-2023-31816 | 1 Content Management System Project | 1 Content Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php. | |||||
| CVE-2023-31779 | 1 Wekan Project | 1 Wekan | 2026-06-17 | N/A | 5.4 MEDIUM |
| Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature. | |||||
| CVE-2023-31757 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian' | |||||
| CVE-2023-31754 | 1 Optimizely | 1 Optimizely Cms | 2026-06-17 | N/A | 4.8 MEDIUM |
| Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel. | |||||
| CVE-2023-31705 | 1 Task Reminder System Project | 1 Task Reminder System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter. | |||||
| CVE-2023-31703 | 1 Escanav | 1 Escan Management Console | 2026-06-17 | N/A | 9.0 CRITICAL |
| Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter. | |||||
| CVE-2023-31699 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 4.8 MEDIUM |
| ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file. | |||||
| CVE-2023-31698 | 1 Bludit | 1 Bludit | 2026-06-17 | N/A | 5.4 MEDIUM |
| Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration). | |||||
| CVE-2023-31664 | 1 Wso2 | 1 Api Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter. | |||||
| CVE-2023-31584 | 1 Silicon Project | 1 Silicon | 2026-06-17 | N/A | 6.1 MEDIUM |
| GitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the User Input field. | |||||
| CVE-2023-31548 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2023-31546 | 1 Dedebiz | 1 Dedebiz | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature. | |||||
| CVE-2023-31544 | 1 Alkacon | 1 Opencms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module. | |||||
