Total
47482 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-40348 | 1 Intern Record System Project | 1 Intern Record System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code. | |||||
| CVE-2022-40325 | 1 Sysaid | 1 Help Desk | 2026-06-17 | N/A | 6.1 MEDIUM |
| SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. | |||||
| CVE-2022-40324 | 1 Sysaid | 1 Help Desk | 2026-06-17 | N/A | 6.1 MEDIUM |
| SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. | |||||
| CVE-2022-40323 | 1 Sysaid | 1 Help Desk | 2026-06-17 | N/A | 6.1 MEDIUM |
| SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. | |||||
| CVE-2022-40322 | 1 Sysaid | 1 Help Desk | 2026-06-17 | N/A | 6.1 MEDIUM |
| SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. | |||||
| CVE-2022-40317 | 1 Openkm | 1 Openkm | 2026-06-17 | N/A | 5.4 MEDIUM |
| OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. | |||||
| CVE-2022-40313 | 2 Fedoraproject, Moodle | 3 Extra Packages For Enterprise Linux, Fedora, Moodle | 2026-06-17 | N/A | 7.1 HIGH |
| Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | |||||
| CVE-2022-40311 | 1 Fatcatapps | 1 Analytics Cat | 2026-06-17 | N/A | 4.8 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress. | |||||
| CVE-2022-40290 | 1 Phppointofsale | 1 Php Point Of Sale | 2026-06-17 | N/A | 6.1 MEDIUM |
| The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allowing attackers to generate an unsafe link that could compromise users. | |||||
| CVE-2022-40289 | 1 Phppointofsale | 1 Php Point Of Sale | 2026-06-17 | N/A | 9.0 CRITICAL |
| The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files. | |||||
| CVE-2022-40288 | 1 Phppointofsale | 1 Php Point Of Sale | 2026-06-17 | N/A | 9.0 CRITICAL |
| The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile. | |||||
| CVE-2022-40287 | 1 Phppointofsale | 1 Php Point Of Sale | 2026-06-17 | N/A | 9.0 CRITICAL |
| The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account. | |||||
| CVE-2022-40257 | 1 Cert | 1 Vince | 2026-06-17 | N/A | 5.4 MEDIUM |
| An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field. | |||||
| CVE-2022-40248 | 1 Cert | 1 Vince | 2026-06-17 | N/A | 5.4 MEDIUM |
| An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field. | |||||
| CVE-2022-40215 | 1 Tabs Project | 1 Tabs | 2026-06-17 | N/A | 3.4 LOW |
| Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress. | |||||
| CVE-2022-40213 | 1 Gsplugins | 1 Gs Testimonial Slider | 2026-06-17 | N/A | 4.1 MEDIUM |
| Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress. | |||||
| CVE-2022-40211 | 1 Givewp | 1 Givewp | 2026-06-17 | N/A | 5.9 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP allows Stored XSS.This issue affects GiveWP: from n/a through 2.25.1. | |||||
| CVE-2022-40209 | 1 Xylusthemes | 1 Wp Smart Import | 2026-06-17 | N/A | 6.1 MEDIUM |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress. | |||||
| CVE-2022-40204 | 1 Digitalalertsystems | 10 Dasdec I, Dasdec I Firmware, Dasdec Ii and 7 more | 2026-06-17 | N/A | 4.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login. | |||||
| CVE-2022-40195 | 1 Loqate | 1 Loqate | 2026-06-17 | N/A | 4.8 MEDIUM |
| Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress. | |||||
