Total
47482 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-39053 | 1 Heimavista | 1 Dark Horse Rpage | 2026-06-17 | N/A | 6.1 MEDIUM |
| Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack. | |||||
| CVE-2022-39050 | 1 Otrs | 1 Otrs | 2026-06-17 | N/A | 4.6 MEDIUM |
| An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap | |||||
| CVE-2022-39049 | 1 Otrs | 1 Otrs | 2026-06-17 | N/A | 3.5 LOW |
| An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. | |||||
| CVE-2022-39048 | 1 Servicenow | 1 Servicenow | 2026-06-17 | N/A | 6.1 MEDIUM |
| A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems. | |||||
| CVE-2022-39035 | 1 Lcnet | 1 Smart Evision | 2026-06-17 | N/A | 6.1 MEDIUM |
| Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack. | |||||
| CVE-2022-39027 | 1 Edetw | 1 U-office Force | 2026-06-17 | N/A | 5.4 MEDIUM |
| U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack. | |||||
| CVE-2022-39026 | 1 Edetw | 1 U-office Force | 2026-06-17 | N/A | 5.4 MEDIUM |
| U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack. | |||||
| CVE-2022-39025 | 1 Edetw | 1 U-office Force | 2026-06-17 | N/A | 6.1 MEDIUM |
| U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack. | |||||
| CVE-2022-39024 | 1 Edetw | 1 U-office Force | 2026-06-17 | N/A | 6.1 MEDIUM |
| U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack. | |||||
| CVE-2022-39020 | 1 Schoolbox | 1 Schoolbox | 2026-06-17 | N/A | 7.6 HIGH |
| Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting. | |||||
| CVE-2022-39017 | 1 M-files | 1 Hubshare | 2026-06-17 | N/A | 8.2 HIGH |
| Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments. | |||||
| CVE-2022-39016 | 1 M-files | 1 Hubshare | 2026-06-17 | N/A | 8.2 HIGH |
| Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload. | |||||
| CVE-2022-38975 | 1 Ec-cube | 1 Ec-cube | 2026-06-17 | N/A | 5.4 MEDIUM |
| DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page. | |||||
| CVE-2022-38972 | 1 Ark-web | 1 A-form | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inject an arbitrary script. | |||||
| CVE-2022-38971 | 1 Themekraft | 1 Post Form Registration Form Profile Form For User Profiles And Content Forms | 2026-06-17 | N/A | 4.7 MEDIUM |
| Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |||||
| CVE-2022-38845 | 1 Espocrm | 1 Espocrm | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser. | |||||
| CVE-2022-38814 | 1 Fiberhome | 2 An5506-02-b, An5506-02-b Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field. | |||||
| CVE-2022-38803 | 1 Zkteco | 1 Biotime | 2026-06-17 | N/A | 6.8 MEDIUM |
| Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting data as a PDF | |||||
| CVE-2022-38802 | 1 Zkteco | 1 Biotime | 2026-06-17 | N/A | 6.2 MEDIUM |
| Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated administrator can read local files by exploiting XSS into a pdf generator when exporting data as a PDF | |||||
| CVE-2022-38801 | 1 Zkteco | 1 Biotime | 2026-06-17 | N/A | 5.4 MEDIUM |
| In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting. | |||||
