Total
47484 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-0891 | 1 Codestag | 1 Stagtools | 2026-06-17 | N/A | 5.4 MEDIUM |
| The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
| CVE-2023-0879 | 1 Btcpayserver | 1 Btcpay Server | 2026-06-17 | N/A | 6.3 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12. | |||||
| CVE-2023-0878 | 1 Nuxt | 1 Nuxt | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1. | |||||
| CVE-2023-0869 | 1 Opennms | 2 Horizon, Meridian | 2026-06-17 | N/A | 5.8 MEDIUM |
| Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. | |||||
| CVE-2023-0868 | 1 Opennms | 2 Horizon, Meridian | 2026-06-17 | N/A | 6.7 MEDIUM |
| Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. | |||||
| CVE-2023-0867 | 1 Opennms | 2 Horizon, Meridian | 2026-06-17 | N/A | 6.7 MEDIUM |
| Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. | |||||
| CVE-2023-0846 | 1 Opennms | 2 Horizon, Meridian | 2026-06-17 | N/A | 6.7 MEDIUM |
| Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. | |||||
| CVE-2023-0844 | 1 Kibokolabs | 1 Namaste\! Lms | 2026-06-17 | N/A | 4.8 MEDIUM |
| The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
| CVE-2023-0840 | 1 Phpcrazy Project | 1 Phpcrazy | 2026-06-17 | 4.0 MEDIUM | 3.5 LOW |
| A vulnerability classified as problematic was found in PHPCrazy 1.1.1. This vulnerability affects unknown code of the file admin/admin.php?action=users&mode=info&user=2. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221086 is the identifier assigned to this vulnerability. | |||||
| CVE-2023-0835 | 1 Markdown-pdf Project | 1 Markdown-pdf | 2026-06-17 | N/A | 8.2 HIGH |
| markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user. | |||||
| CVE-2023-0829 | 1 Plesk | 1 Plesk | 2026-06-17 | N/A | 8.8 HIGH |
| Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription. | |||||
| CVE-2023-0828 | 1 Pandorafms | 1 Pandora Fms | 2026-06-17 | N/A | 6.7 MEDIUM |
| Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms. | |||||
| CVE-2023-0827 | 1 Pimcore | 1 Pimcore | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17. | |||||
| CVE-2023-0810 | 1 Btcpayserver | 1 Btcpayserver | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11. | |||||
| CVE-2023-0794 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | N/A | 8.3 HIGH |
| Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | |||||
| CVE-2023-0791 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | N/A | 8.3 HIGH |
| Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | |||||
| CVE-2023-0787 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | N/A | 8.1 HIGH |
| Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | |||||
| CVE-2023-0786 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | N/A | 8.4 HIGH |
| Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | |||||
| CVE-2023-0776 | 1 Baicells | 8 Neutrino 430, Neutrino 430 Firmware, Nova430e and 5 more | 2026-06-17 | N/A | 8.1 HIGH |
| Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce. | |||||
| CVE-2023-0769 | 1 Hiweb | 1 Migration Simple | 2026-06-17 | N/A | 6.1 MEDIUM |
| The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins. | |||||
