Total
47493 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-30746 | 1 Booqable | 1 Rental Software Booqable Rental | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Booqable Rental Software Booqable Rental plugin <= 2.4.15 versions. | |||||
| CVE-2023-30745 | 1 Ip Metaboxes Project | 1 Ip Metaboxes | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Phan Chuong IP Metaboxes plugin <= 2.1.1 versions. | |||||
| CVE-2023-30743 | 1 Sap | 1 Sapui5 | 2026-06-17 | N/A | 7.1 HIGH |
| Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the absence of URL validation by the application, the vulnerability could lead to the attacker reading or modifying user’s information through phishing attack. | |||||
| CVE-2023-30742 | 1 Sap | 2 Customer Relationship Management S4fnd, Customer Relationship Management Webclient Ui | 2026-06-17 | N/A | 6.1 MEDIUM |
| SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.An attacker could store a malicious URL and lure the victim to click, causing the script supplied by the attacker to execute in the victim user's session. The information from the victim's session could then be modified or read by the attacker. | |||||
| CVE-2023-30741 | 1 Sap | 1 Businessobjects Business Intelligence | 2026-06-17 | N/A | 6.1 MEDIUM |
| Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application. | |||||
| CVE-2023-30639 | 1 Archerirm | 1 Archer | 2026-06-17 | N/A | 7.1 HIGH |
| Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release. | |||||
| CVE-2023-30627 | 1 Jellyfin | 1 Jellyfin | 2026-06-17 | N/A | 9.0 CRITICAL |
| jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When combined with CVE-2023-30626, this results in remote code execution on the Jellyfin instance in the context of the user who's running it. This issue is patched in version 10.8.10. There are no known workarounds. | |||||
| CVE-2023-30619 | 1 Enalean | 1 Tuleap | 2026-06-17 | N/A | 5.4 MEDIUM |
| Tuleap Open ALM is a Libre and Open Source tool for end to end traceability of application and system developments. The title of an artifact is not properly escaped in the tooltip. A malicious user with the capability to create an artifact or to edit a field title could force victim to execute uncontrolled code. This issue has been patched in version 14.7.99.143. | |||||
| CVE-2023-30615 | 1 Dfir-iris | 1 Iris | 2026-06-17 | N/A | 6.3 MEDIUM |
| Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations . The vulnerability in allows an attacker to inject malicious scripts into the application, which are then executed when a user visits the affected locations. This can lead to unauthorized access, data theft, or other malicious activities. An attacker need to be authenticated on the application to exploit this vulnerability. The issue was patched in version 2.2.1 of iris-web. | |||||
| CVE-2023-30614 | 1 Pay Project | 1 Pay | 2026-06-17 | N/A | 7.1 HIGH |
| Pay is a payments engine for Ruby on Rails 6.0 and higher. In versions prior to 6.3.2 a payments info page of Pay is susceptible to reflected Cross-site scripting. An attacker could create a working URL that renders a javascript link to a user on a Rails application that integrates Pay. This URL could be distributed via email to specifically target certain individuals. If the targeted application contains a functionality to submit user-generated content (such as comments) the attacker could even distribute the URL using that functionality. This has been patched in version 6.3.2 and above. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-30564 | 1 Bd | 1 Alaris Systems Manager | 2026-06-17 | N/A | 6.9 MEDIUM |
| Alaris Systems Manager does not perform input validation during the Device Import Function. | |||||
| CVE-2023-30563 | 1 Bd | 1 Alaris Systems Manager | 2026-06-17 | N/A | 8.2 HIGH |
| A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. | |||||
| CVE-2023-30538 | 1 Discourse | 1 Discourse | 2026-06-17 | N/A | 5.4 MEDIUM |
| Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacker can execute arbitrary JavaScript on the users’ browsers by uploading a crafted SVG file. This issue is patched in the latest stable and tests-passed versions of Discourse. Users are advised to upgrade. For users unable to upgrade there are two possible workarounds: enable CDN handing of uploads (and ensure the CDN sanitizes SVG files) or disable SVG file uploads by ensuring that the `authorized extensions` site setting does not include `svg` (or reset that setting to the default, by default Discourse doesn't enable SVG uploads by users). | |||||
| CVE-2023-30520 | 1 Jenkins | 1 Quay.io Trigger | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Quay.io trigger webhook payloads. | |||||
| CVE-2023-30500 | 1 Wpforms | 2 Contact Form, Wpforms | 2026-06-17 | N/A | 5.8 MEDIUM |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions. | |||||
| CVE-2023-30499 | 1 Foliovision | 1 Fv Flowplayer Video Player | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions. | |||||
| CVE-2023-30498 | 1 Codeflavors | 1 Vimeotheque | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 versions. | |||||
| CVE-2023-30497 | 1 Simonchuang | 1 Wp Line Notify | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Simon Chuang WP LINE Notify plugin <= 1.4.4 versions. | |||||
| CVE-2023-30496 | 1 Mage-people | 1 Bus Ticket Booking With Seat Reservation | 2026-06-17 | N/A | 7.1 HIGH |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions. | |||||
| CVE-2023-30494 | 1 Imagerecycle | 1 Imagerecycle Pdf \& Image Compression | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions. | |||||
