Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24687 1 Mojoportal 1 Mojoportal 2026-06-17 N/A 5.4 MEDIUM
Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtCompanyName parameter.
CVE-2023-24686 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 4.8 MEDIUM
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.
CVE-2023-24675 1 Bludit 1 Bludit 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.
CVE-2023-24657 1 Phpipam 1 Phpipam 2026-06-17 N/A 6.1 MEDIUM
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
CVE-2023-24651 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 5.4 MEDIUM
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.
CVE-2023-24648 1 Zippy 1 Zstore 2026-06-17 N/A 6.1 MEDIUM
Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php.
CVE-2023-24602 1 Open-xchange 1 Ox App Suite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
CVE-2023-24601 1 Open-xchange 1 Ox App Suite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
CVE-2023-24529 1 Sap 1 Netweaver As Abap Business Server Pages 2026-06-17 N/A 6.1 MEDIUM
Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to hijack a user session, read and modify some sensitive information.
CVE-2023-24525 1 Sap 2 Customer Relationship Management Webclient Ui, S4fnd 2026-06-17 N/A 4.3 MEDIUM
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
CVE-2023-24522 1 Sap 1 Netweaver Application Server Abap 2026-06-17 N/A 6.1 MEDIUM
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.
CVE-2023-24521 1 Sap 1 Netweaver As Abap Business Server Pages 2026-06-17 N/A 6.1 MEDIUM
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.
CVE-2023-24516 1 Pandorafms 1 Pandora Fms 2026-06-17 N/A 5.9 MEDIUM
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.
CVE-2023-24514 1 Pandorafms 1 Pandora Fms 2026-06-17 N/A 6.3 MEDIUM
Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.
CVE-2023-24508 1 Baicells 6 Nova227, Nova233, Nova243 and 3 more 2026-06-17 N/A 8.1 HIGH
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce. 
CVE-2023-24494 1 Tenable 1 Tenable.sc 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session.
CVE-2023-24488 1 Citrix 2 Application Delivery Controller, Gateway 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting
CVE-2023-24469 1 Microfocus 1 Arcsight Logger 2026-06-17 N/A 6.1 MEDIUM
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
CVE-2023-24464 1 Buffalo 14 Bs-gs2008, Bs-gs2008 Firmware, Bs-gs2008p and 11 more 2026-06-17 N/A 5.4 MEDIUM
Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
CVE-2023-24420 1 Zestard 1 Admin Side Data Storage For Contact Form 7 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.