Total
47482 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-35275 | 1 Algolplus | 1 Advanced Order Export For Woocommerce | 2026-06-17 | N/A | 4.8 MEDIUM |
| Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress. | |||||
| CVE-2022-35251 | 1 Rocket.chat | 1 Rocket.chat | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to manipulate not only the style of it, but will also be able to block functionality as well as hijacking the content of targeted users. Hence the payloads are stored in messages, it is a persistent attack vector, which will trigger as soon as the message gets viewed. | |||||
| CVE-2022-35230 | 1 Zabbix | 1 Zabbix | 2026-06-17 | 3.5 LOW | 3.7 LOW |
| An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. | |||||
| CVE-2022-35229 | 1 Zabbix | 1 Zabbix | 2026-06-17 | 3.5 LOW | 3.7 LOW |
| An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. | |||||
| CVE-2022-35227 | 1 Sap | 1 Netweaver Enterprise Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the attacker to execute arbitrary script code which could lead to stealing or modifying of authentication information of the user, such as data relating to his or her current session. | |||||
| CVE-2022-35226 | 1 Sap | 1 Data Services | 2026-06-17 | N/A | 6.1 MEDIUM |
| SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console. | |||||
| CVE-2022-35225 | 1 Sap | 1 Netweaver Enterprise Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data. | |||||
| CVE-2022-35224 | 1 Sap | 1 Enterprise Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim�s web browser session. | |||||
| CVE-2022-35213 | 1 Ecommerce-codeigniter-bootstrap Project | 1 Ecommerce-codeigniter-bootstrap | 2026-06-17 | N/A | 6.1 MEDIUM |
| Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | |||||
| CVE-2022-35212 | 1 Oscommerce | 1 Oscommerce | 2026-06-17 | N/A | 6.1 MEDIUM |
| osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error(). | |||||
| CVE-2022-35194 | 1 Testlink | 1 Testlink | 2026-06-17 | N/A | 5.4 MEDIUM |
| TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php. | |||||
| CVE-2022-35174 | 1 Getkirby | 1 Starterkit | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field. | |||||
| CVE-2022-35172 | 1 Sap | 1 Netweaver Enterprise Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |||||
| CVE-2022-35170 | 1 Sap | 1 Netweaver Enterprise Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data. | |||||
| CVE-2022-35163 | 1 Complete Online Job Search System Project | 1 Complete Online Job Search System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at /category/controller.php?action=edit. | |||||
| CVE-2022-35162 | 1 Complete Online Job Search System Project | 1 Complete Online Job Search System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the CATEGORY parameter at /category/controller.php?action=edit. | |||||
| CVE-2022-35151 | 1 Keking | 1 Kkfileview | 2026-06-17 | N/A | 6.1 MEDIUM |
| kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java. | |||||
| CVE-2022-35144 | 1 Raneto Project | 1 Raneto | 2026-06-17 | N/A | 4.8 MEDIUM |
| Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | |||||
| CVE-2022-35137 | 1 Dgiotcloud | 1 Dgiot | 2026-06-17 | N/A | 5.4 MEDIUM |
| DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | |||||
| CVE-2022-35134 | 1 Boodskap | 1 Iot Platform | 2026-06-17 | N/A | 5.4 MEDIUM |
| Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability. | |||||
