Total
47482 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-38790 | 1 Weave.works | 1 Gitops | 2026-06-17 | N/A | 5.4 MEDIUM |
| Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise UI via a GitopsCluster dashboard link. An annotation can be added to a GitopsCluster custom resource. | |||||
| CVE-2022-38758 | 1 Netiq | 1 Imanager | 2026-06-17 | N/A | 7.2 HIGH |
| Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL. | |||||
| CVE-2022-38754 | 1 Microfocus | 2 Operations Bridge, Operations Bridge Manager | 2026-06-17 | N/A | 8.0 HIGH |
| A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11. | |||||
| CVE-2022-38724 | 1 Silverstripe | 3 Asset Admin, Assets, Framework | 2026-06-17 | N/A | 5.4 MEDIUM |
| Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. | |||||
| CVE-2022-38723 | 1 Gravitee | 1 Api Management | 2026-06-17 | N/A | 8.6 HIGH |
| Gravitee API Management before 3.15.13 allows path traversal through HTML injection. | |||||
| CVE-2022-38709 | 2 Ibm, Microsoft | 2 Robotic Process Automation For Cloud Pak, Windows | 2026-06-17 | N/A | 6.1 MEDIUM |
| IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 234291. | |||||
| CVE-2022-38703 | 1 Maxfoundry | 1 Maxbuttons | 2026-06-17 | N/A | 3.4 LOW |
| Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress | |||||
| CVE-2022-38664 | 1 Jenkins | 1 Job Configuration History | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names. | |||||
| CVE-2022-38653 | 1 Hcltech | 1 Digital Experience | 2026-06-17 | N/A | 2.0 LOW |
| In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded. | |||||
| CVE-2022-38639 | 1 Inkdrop | 1 Markdown Nice | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field. | |||||
| CVE-2022-38550 | 1 Jeesns | 1 Jeesns | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2022-38545 | 1 Valine.js | 1 Valine | 2026-06-17 | N/A | 9.6 CRITICAL |
| Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request. | |||||
| CVE-2022-38527 | 1 Ucms Project | 1 Ucms | 2026-06-17 | N/A | 6.1 MEDIUM |
| UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page. | |||||
| CVE-2022-38489 | 1 Easyvista | 1 Service Manager | 2026-06-17 | N/A | 4.8 MEDIUM |
| An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably. | |||||
| CVE-2022-38481 | 1 Mega | 1 Hopex | 2026-06-17 | N/A | 6.1 MEDIUM |
| An issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP2. The application is prone to reflected Cross-site Scripting (XSS) in several features. | |||||
| CVE-2022-38467 | 1 Crmperks | 1 Crm Perks Forms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver. | |||||
| CVE-2022-38463 | 1 Servicenow | 1 Servicenow | 2026-06-17 | N/A | 6.1 MEDIUM |
| ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality. | |||||
| CVE-2022-38462 | 1 Silverstripe | 1 Framework | 2026-06-17 | N/A | 6.1 MEDIUM |
| Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | |||||
| CVE-2022-38460 | 1 Notice Board Project | 1 Notice Board | 2026-06-17 | N/A | 5.4 MEDIUM |
| Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NOTICE BOARD plugin <= 1.1 at WordPress. | |||||
| CVE-2022-38439 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2026-06-17 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM. | |||||
