Total
47486 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-26788 | 1 Veritas | 1 Netbackup Appliance Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. | |||||
| CVE-2023-26777 | 1 Uptime Kuma Project | 1 Uptime Kuma | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint. | |||||
| CVE-2023-26776 | 1 Monitorr | 1 Monitorr | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the title parameter of the post_receiver-services.php file. | |||||
| CVE-2023-26773 | 1 Sales Tracker Management System Project | 1 Sales Tracker Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file. | |||||
| CVE-2023-26771 | 1 Taskcafe Project | 1 Taskcafe | 2026-06-17 | N/A | 6.5 MEDIUM |
| Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file. | |||||
| CVE-2023-26750 | 1 Yiiframework | 1 Yii | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework. | |||||
| CVE-2023-26692 | 1 Zcbs | 3 Zbbs, Zcbs, Zpbs | 2026-06-17 | N/A | 6.1 MEDIUM |
| ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-26688 | 1 Cs-cart | 1 Cs-cart Multivendor | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface. | |||||
| CVE-2023-26608 | 1 Vxcontrol | 1 Soldr | 2026-06-17 | N/A | 5.4 MEDIUM |
| SOLDR (System of Orchestration, Lifecycle control, Detection and Response) 1.1.0 allows stored XSS via the module editor. | |||||
| CVE-2023-26599 | 1 Uniguest | 1 Tripleplay | 2026-06-17 | N/A | 6.1 MEDIUM |
| XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client-side code to run as an authenticated user via a crafted link. | |||||
| CVE-2023-26577 | 1 Idattend | 1 Idweb | 2026-06-17 | N/A | 7.5 HIGH |
| Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the browsing session of the logged in user. | |||||
| CVE-2023-26541 | 1 Asmember Project | 1 Asmember | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions. | |||||
| CVE-2023-26539 | 1 Advanced Text Widget Project | 1 Advanced Text Widget | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versions. | |||||
| CVE-2023-26538 | 1 Chat Bee Project | 1 Chat Bee | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamyabsoft Chat Bee plugin <= 1.1.0 versions. | |||||
| CVE-2023-26537 | 1 Wp No External Links Project | 1 Wp No External Links | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions. | |||||
| CVE-2023-26536 | 1 Followmedarling | 1 Spotify-play-button-for-wordpress | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.05 versions. | |||||
| CVE-2023-26534 | 1 Onewebsite | 1 Wp Repost | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions. | |||||
| CVE-2023-26530 | 1 Updraftplus | 1 Updraft | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions. | |||||
| CVE-2023-26529 | 1 Dupeoff Project | 1 Dupeoff | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DupeOff.Com DupeOff plugin <= 1.6 versions. | |||||
| CVE-2023-26528 | 1 Shipyaari | 1 Shipping Management | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jinit9906 Shipyaari Shipping Management plugin <= 1.0 versions. | |||||
