Total
47492 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-29837 | 1 Exelysis | 1 Exelysis Unified Communications Solution | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Exelysis Unified Communication Solution (EUCS) v.1.0 allows a remote attacker to gain privileges via the URL path of the eucsAdmin login web page. | |||||
| CVE-2023-29836 | 1 Exelysis | 1 Exelysis Unified Communications Solution | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form. | |||||
| CVE-2023-29808 | 1 Companymaps Project | 1 Companymaps | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code. | |||||
| CVE-2023-29791 | 1 Kodcloud | 1 Kodbox | 2026-06-17 | N/A | 6.1 MEDIUM |
| kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. | |||||
| CVE-2023-29774 | 1 Iteachyou | 1 Dreamer Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS). | |||||
| CVE-2023-29772 | 1 Asus | 2 Rt-ac51u, Rt-ac51u Firmware | 2026-06-17 | N/A | 5.2 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to inject arbitrary web script or HTML via a malicious network request. | |||||
| CVE-2023-29720 | 1 Sofawiki Project | 1 Sofawiki | 2026-06-17 | N/A | 6.1 MEDIUM |
| SofaWiki <=3.8.9 is vulnerable to Cross Site Scripting (XSS) via index.php. | |||||
| CVE-2023-29714 | 1 Vadesecure | 1 Secure Gateway | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via the username, password, and language cookies parameter. | |||||
| CVE-2023-29713 | 1 Vadesecure | 1 Secure Gateway | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory. | |||||
| CVE-2023-29712 | 1 Vadesecure | 1 Secure Gateway | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter. | |||||
| CVE-2023-29707 | 1 Gbcom | 1 Lac Web Control Center | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device. | |||||
| CVE-2023-29643 | 1 Perfree | 1 Perfreeblog | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function. | |||||
| CVE-2023-29641 | 1 Ipandao | 1 Editor.md | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. | |||||
| CVE-2023-29639 | 1 Zhenfeng13 | 1 My Blog | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the default configuration not utilizing MyBlogUtils.cleanString. | |||||
| CVE-2023-29638 | 1 Winterchen | 1 My-site | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in WinterChenS my-site before commit 3f0423da6d5200c7a46e200da145c1f54ee18548, allows attackers to inject arbitrary web script or HTML via editing blog articles. | |||||
| CVE-2023-29637 | 1 Qbian61 Forum-java Project | 1 Qbian61 Forum-java | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML via editing the article content in the "article editor" page. | |||||
| CVE-2023-29636 | 1 Zhenfeng13 | 1 My Blog | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString. | |||||
| CVE-2023-29623 | 1 Purchase Order Management Project | 1 Purchase Order Management | 2026-06-17 | N/A | 6.1 MEDIUM |
| Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php. | |||||
| CVE-2023-29528 | 1 Xwiki | 1 Commons | 2026-06-17 | N/A | 9.0 CRITICAL |
| XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML comments. As a consequence, any code relying on this "restricted" mode for security is vulnerable to JavaScript injection ("cross-site scripting"/XSS). When a privileged user with programming rights visits such a comment in XWiki, the malicious JavaScript code is executed in the context of the user session. This allows server-side code execution with programming rights, impacting the confidentiality, integrity and availability of the XWiki instance. This problem has been patched in XWiki 14.10, HTML comments are now removed in restricted mode and a check has been introduced that ensures that comments don't start with `>`. There are no known workarounds apart from upgrading to a version including the fix. | |||||
| CVE-2023-29515 | 1 Xwiki | 1 Xwiki | 2026-06-17 | N/A | 7.7 HIGH |
| XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can create a space can become admin of that space through App Within Minutes. The admin right implies the script right and thus allows JavaScript injection. The vulnerability can be exploited by creating an app in App Within Minutes. If the button should be disabled because the user doesn't have global edit right, the app can also be created by directly opening `/xwiki/bin/view/AppWithinMinutes/CreateApplication?wizard=true` on the XWiki installation. This has been patched in XWiki 13.10.11, 14.4.8, 14.10.1 and 15.0 RC1 by not granting the space admin right if the user doesn't have script right on the space where the app is created. Error message are displayed to warn the user that the app will be broken in this case. Users who became space admin through this vulnerability won't loose the space admin right due to the fix, so it is advised to check if all users who created AWM apps should keep their space admin rights. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
