Total
47486 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-24687 | 1 Mojoportal | 1 Mojoportal | 2026-06-17 | N/A | 5.4 MEDIUM |
| Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtCompanyName parameter. | |||||
| CVE-2023-24686 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 4.8 MEDIUM |
| An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file. | |||||
| CVE-2023-24675 | 1 Bludit | 1 Bludit | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL. | |||||
| CVE-2023-24657 | 1 Phpipam | 1 Phpipam | 2026-06-17 | N/A | 6.1 MEDIUM |
| phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. | |||||
| CVE-2023-24651 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page. | |||||
| CVE-2023-24648 | 1 Zippy | 1 Zstore | 2026-06-17 | N/A | 6.1 MEDIUM |
| Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php. | |||||
| CVE-2023-24602 | 1 Open-xchange | 1 Ox App Suite | 2026-06-17 | N/A | 6.1 MEDIUM |
| OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. | |||||
| CVE-2023-24601 | 1 Open-xchange | 1 Ox App Suite | 2026-06-17 | N/A | 6.1 MEDIUM |
| OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. | |||||
| CVE-2023-24529 | 1 Sap | 1 Netweaver As Abap Business Server Pages | 2026-06-17 | N/A | 6.1 MEDIUM |
| Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to hijack a user session, read and modify some sensitive information. | |||||
| CVE-2023-24525 | 1 Sap | 2 Customer Relationship Management Webclient Ui, S4fnd | 2026-06-17 | N/A | 4.3 MEDIUM |
| SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application. | |||||
| CVE-2023-24522 | 1 Sap | 1 Netweaver Application Server Abap | 2026-06-17 | N/A | 6.1 MEDIUM |
| Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application. | |||||
| CVE-2023-24521 | 1 Sap | 1 Netweaver As Abap Business Server Pages | 2026-06-17 | N/A | 6.1 MEDIUM |
| Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application. | |||||
| CVE-2023-24516 | 1 Pandorafms | 1 Pandora Fms | 2026-06-17 | N/A | 5.9 MEDIUM |
| Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms. | |||||
| CVE-2023-24514 | 1 Pandorafms | 1 Pandora Fms | 2026-06-17 | N/A | 6.3 MEDIUM |
| Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms. | |||||
| CVE-2023-24508 | 1 Baicells | 6 Nova227, Nova233, Nova243 and 3 more | 2026-06-17 | N/A | 8.1 HIGH |
| Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce. | |||||
| CVE-2023-24494 | 1 Tenable | 1 Tenable.sc | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session. | |||||
| CVE-2023-24488 | 1 Citrix | 2 Application Delivery Controller, Gateway | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | |||||
| CVE-2023-24469 | 1 Microfocus | 1 Arcsight Logger | 2026-06-17 | N/A | 6.1 MEDIUM |
| Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 | |||||
| CVE-2023-24464 | 1 Buffalo | 14 Bs-gs2008, Bs-gs2008 Firmware, Bs-gs2008p and 11 more | 2026-06-17 | N/A | 5.4 MEDIUM |
| Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier | |||||
| CVE-2023-24420 | 1 Zestard | 1 Admin Side Data Storage For Contact Form 7 | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions. | |||||
