Total
47484 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-0747 | 1 Btcpayserver | 1 Btcpayserver | 2026-06-17 | N/A | 5.5 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. | |||||
| CVE-2023-0746 | 1 Gigamon | 1 Gigavue-os | 2026-06-17 | N/A | 6.3 MEDIUM |
| The help page in GigaVUE-FM, when using GigaVUE-OS software version 5.0 202, does not require an authenticated user. An attacker could enforce a user into inserting malicious JavaScript code into the URI, that could lead to a Reflected Cross site Scripting. | |||||
| CVE-2023-0743 | 1 Answer | 1 Answer | 2026-06-17 | N/A | 9.0 CRITICAL |
| Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4. | |||||
| CVE-2023-0742 | 1 Answer | 1 Answer | 2026-06-17 | N/A | 9.0 CRITICAL |
| Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | |||||
| CVE-2023-0741 | 1 Answer | 1 Answer | 2026-06-17 | N/A | 9.0 CRITICAL |
| Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4. | |||||
| CVE-2023-0740 | 1 Answer | 1 Answer | 2026-06-17 | N/A | 9.0 CRITICAL |
| Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | |||||
| CVE-2023-0738 | 1 Orangescrum | 1 Orangescrum | 2026-06-17 | N/A | 6.1 MEDIUM |
| OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html. | |||||
| CVE-2023-0736 | 1 Wallabag | 1 Wallabag | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4. | |||||
| CVE-2023-0732 | 1 Oretnom23 | 1 Online Eyewear Shop | 2026-06-17 | 4.0 MEDIUM | 3.5 LOW |
| A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact leads to cross site scripting. The attack can be launched remotely. The identifier VDB-220369 was assigned to this vulnerability. | |||||
| CVE-2023-0731 | 1 Interactive Geo Maps Project | 1 Interactive Geo Maps | 2026-06-17 | N/A | 6.4 MEDIUM |
| The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2023-0710 | 1 Wpmet | 1 Metform Elementor Contact Form Builder | 2026-06-17 | N/A | 4.9 MEDIUM |
| The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a a page containing the shortcode when the submission id is present in the query string. Note that getting the JavaScript to execute requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database. Additionally this requires successful payment, increasing the complexity. | |||||
| CVE-2023-0709 | 1 Wpmet | 1 Metform Elementor Contact Form Builder | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a a page containing the shortcode when the submission id is present in the query string. Note that getting the JavaScript to execute requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database. | |||||
| CVE-2023-0708 | 1 Wpmet | 1 Metform Elementor Contact Form Builder | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a a page containing the shortcode when the submission id is present in the query string. Note that getting the JavaScript to execute requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database. | |||||
| CVE-2023-0695 | 1 Wpmet | 1 Metform Elementor Contact Form Builder | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a specific link. Note that getting the JavaScript to execute still requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database. | |||||
| CVE-2023-0677 | 1 Phpipam | 1 Phpipam | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1. | |||||
| CVE-2023-0676 | 1 Phpipam | 1 Phpipam | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1. | |||||
| CVE-2023-0650 | 1 Yetanotherforum | 1 Yaf.net | 2026-06-17 | 4.0 MEDIUM | 3.5 LOW |
| A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.12 is able to address this issue. The identifier of the patch is a1442a2bacc3335461b44c250e81f8d99c60735f. It is recommended to upgrade the affected component. The identifier VDB-220037 was assigned to this vulnerability. | |||||
| CVE-2023-0639 | 1 Trendnet | 2 Tew-652brp, Tew-652brp Firmware | 2026-06-17 | 3.3 LOW | 2.4 LOW |
| A vulnerability was found in TRENDnet TEW-652BRP 3.04b01 and classified as problematic. This issue affects some unknown processing of the file get_set.ccp of the component Web Management Interface. The manipulation of the argument nextPage leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-220019. | |||||
| CVE-2023-0625 | 1 Docker | 1 Docker Desktop | 2026-06-17 | N/A | 8.0 HIGH |
| Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0. | |||||
| CVE-2023-0624 | 1 Orangescrum | 1 Orangescrum | 2026-06-17 | N/A | 6.1 MEDIUM |
| OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html. | |||||
