Total
47482 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-36748 | 1 Picuploader Project | 1 Picuploader | 2026-06-17 | N/A | 6.1 MEDIUM |
| PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php. | |||||
| CVE-2022-36747 | 1 Cobub | 1 Razor | 2026-06-17 | N/A | 6.1 MEDIUM |
| Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel(). | |||||
| CVE-2022-36746 | 1 Librenms | 1 Librenms | 2026-06-17 | N/A | 6.1 MEDIUM |
| LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php. | |||||
| CVE-2022-36745 | 1 Librenms | 1 Librenms | 2026-06-17 | N/A | 6.1 MEDIUM |
| LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php. | |||||
| CVE-2022-36677 | 1 Lynchjames | 1 Obsidian Mind Map | 2026-06-17 | N/A | 6.1 MEDIUM |
| Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document. | |||||
| CVE-2022-36668 | 1 Garage Management System Project | 1 Garage Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for further attack vector. | |||||
| CVE-2022-36664 | 1 Adiscon | 1 Password Manager For Iis | 2026-06-17 | N/A | 6.1 MEDIUM |
| Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. | |||||
| CVE-2022-36657 | 1 Library Management System Project | 1 Library Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /librarian/edit_book_details.php. | |||||
| CVE-2022-36639 | 1 Garage Management System Project | 1 Garage Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | |||||
| CVE-2022-36637 | 1 Garage Management System Project | 1 Garage Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter at /brand.php. | |||||
| CVE-2022-36600 | 1 Blogengine | 1 Blogengine.net | 2026-06-17 | N/A | 4.8 MEDIUM |
| BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | |||||
| CVE-2022-36583 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 6.1 MEDIUM |
| DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters. | |||||
| CVE-2022-36573 | 1 Pagekit | 1 Pagekit | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit. | |||||
| CVE-2022-36548 | 1 Hashenudara | 1 Edoc-doctor-appointment-system | 2026-06-17 | N/A | 5.4 MEDIUM |
| Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field. | |||||
| CVE-2022-36547 | 1 Hashenudara | 1 Edoc-doctor-appointment-system | 2026-06-17 | N/A | 6.1 MEDIUM |
| Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field. | |||||
| CVE-2022-36527 | 1 Jflyfox | 1 Jfinal Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module. | |||||
| CVE-2022-36433 | 1 Amasty | 1 Amasty Blog Pro | 2026-06-17 | N/A | 6.1 MEDIUM |
| The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save. | |||||
| CVE-2022-36432 | 1 Amasty | 1 Blog Pro | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response. | |||||
| CVE-2022-36428 | 1 Rockcontent | 1 Rock Convert | 2026-06-17 | N/A | 4.8 MEDIUM |
| Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress. | |||||
| CVE-2022-36417 | 1 3d Tag Cloud Project | 1 3d Tag Cloud | 2026-06-17 | N/A | 6.1 MEDIUM |
| Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <= 3.8 at WordPress. | |||||
