Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-38790 1 Weave.works 1 Gitops 2026-06-17 N/A 5.4 MEDIUM
Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise UI via a GitopsCluster dashboard link. An annotation can be added to a GitopsCluster custom resource.
CVE-2022-38758 1 Netiq 1 Imanager 2026-06-17 N/A 7.2 HIGH
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL.
CVE-2022-38754 1 Microfocus 2 Operations Bridge, Operations Bridge Manager 2026-06-17 N/A 8.0 HIGH
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11.
CVE-2022-38724 1 Silverstripe 3 Asset Admin, Assets, Framework 2026-06-17 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
CVE-2022-38723 1 Gravitee 1 Api Management 2026-06-17 N/A 8.6 HIGH
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
CVE-2022-38709 2 Ibm, Microsoft 2 Robotic Process Automation For Cloud Pak, Windows 2026-06-17 N/A 6.1 MEDIUM
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 234291.
CVE-2022-38703 1 Maxfoundry 1 Maxbuttons 2026-06-17 N/A 3.4 LOW
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress
CVE-2022-38664 1 Jenkins 1 Job Configuration History 2026-06-17 N/A 5.4 MEDIUM
Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.
CVE-2022-38653 1 Hcltech 1 Digital Experience 2026-06-17 N/A 2.0 LOW
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
CVE-2022-38639 1 Inkdrop 1 Markdown Nice 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.
CVE-2022-38550 1 Jeesns 1 Jeesns 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-38545 1 Valine.js 1 Valine 2026-06-17 N/A 9.6 CRITICAL
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
CVE-2022-38527 1 Ucms Project 1 Ucms 2026-06-17 N/A 6.1 MEDIUM
UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.
CVE-2022-38489 1 Easyvista 1 Service Manager 2026-06-17 N/A 4.8 MEDIUM
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably.
CVE-2022-38481 1 Mega 1 Hopex 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP2. The application is prone to reflected Cross-site Scripting (XSS) in several features.
CVE-2022-38467 1 Crmperks 1 Crm Perks Forms 2026-06-17 N/A 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
CVE-2022-38463 1 Servicenow 1 Servicenow 2026-06-17 N/A 6.1 MEDIUM
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
CVE-2022-38462 1 Silverstripe 1 Framework 2026-06-17 N/A 6.1 MEDIUM
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
CVE-2022-38460 1 Notice Board Project 1 Notice Board 2026-06-17 N/A 5.4 MEDIUM
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NOTICE BOARD plugin <= 1.1 at WordPress.
CVE-2022-38439 1 Adobe 2 Experience Manager, Experience Manager Cloud Service 2026-06-17 N/A 5.4 MEDIUM
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.