Total
47492 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-28014 | 1 Hcltech | 1 Bigfix Mobile | 2026-06-17 | N/A | 6.6 MEDIUM |
| HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application. | |||||
| CVE-2023-28013 | 1 Hcltech | 1 Verse | 2026-06-17 | N/A | 6.5 MEDIUM |
| HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. | |||||
| CVE-2023-27990 | 1 Zyxel | 38 Atp100, Atp100 Firmware, Atp100w and 35 more | 2026-06-17 | N/A | 4.8 MEDIUM |
| The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device. | |||||
| CVE-2023-27926 | 1 Vektor-inc | 1 Vk All In One Expansion Unit | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script. | |||||
| CVE-2023-27925 | 1 Vektor-inc | 1 Vk Blocks | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. | |||||
| CVE-2023-27923 | 1 Vektor-inc | 1 Vk Blocks | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. | |||||
| CVE-2023-27922 | 1 Thenewsletterplugin | 1 Newsletter | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script. | |||||
| CVE-2023-27918 | 1 Tms-outsource | 1 Amelia | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL. | |||||
| CVE-2023-27905 | 1 Jenkins | 1 Update-center2 | 2026-06-17 | N/A | 9.6 CRITICAL |
| Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |||||
| CVE-2023-27898 | 1 Jenkins | 1 Jenkins | 2026-06-17 | N/A | 9.6 CRITICAL |
| Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances. | |||||
| CVE-2023-27890 | 1 Export User Project | 1 Export User | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2023-27888 | 1 Sitebridge | 1 Joruri Gw | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject an arbitrary script via Message Memo function of the affected product. | |||||
| CVE-2023-27864 | 1 Ibm | 1 Maximo Asset Management | 2026-06-17 | N/A | 5.4 MEDIUM |
| IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 249327. | |||||
| CVE-2023-27777 | 1 Online Jewelry Shop Project | 1 Online Jewelry Shop | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL. | |||||
| CVE-2023-27776 | 1 Online Jewelry Shop Project | 1 Online Jewelry Shop | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter. | |||||
| CVE-2023-27739 | 1 Easyxdm | 1 Easyxdm | 2026-06-17 | N/A | 6.1 MEDIUM |
| easyXDM 2.5 allows XSS via the xdm_e parameter. | |||||
| CVE-2023-27711 | 1 Typecho | 1 Typecho | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component. | |||||
| CVE-2023-27641 | 1 Lsoft | 1 Listserv | 2026-06-17 | N/A | 6.1 MEDIUM |
| The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL. | |||||
| CVE-2023-27636 | 1 Progress | 1 Sitefinity | 2026-06-17 | N/A | 5.4 MEDIUM |
| Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. | |||||
| CVE-2023-27631 | 1 Mmrs151 | 1 Daily Prayer Time | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions. | |||||
