Total
47243 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-45992 | 1 Commscope | 1 Ruckus Cloudpath Enrollment System | 2026-07-09 | N/A | 9.6 CRITICAL |
| A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system. | |||||
| CVE-2023-43232 | 1 Dedebiz | 1 Dedebiz | 2026-07-09 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter. | |||||
| CVE-2023-42426 | 1 Froala | 1 Froala Editor | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component. | |||||
| CVE-2023-42399 | 1 Xdsoft | 1 Joditeditor | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component. | |||||
| CVE-2023-41453 | 1 Phpkobo | 1 Ajaxnewsticker | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component. | |||||
| CVE-2023-41451 | 1 Phpkobo | 1 Ajaxnewsticker | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component. | |||||
| CVE-2023-41448 | 1 Phpkobo | 1 Ajaxnewsticker | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component. | |||||
| CVE-2023-41447 | 1 Phpkobo | 1 Ajaxnewsticker | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component. | |||||
| CVE-2023-41446 | 1 Phpkobo | 1 Ajaxnewsticker | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component. | |||||
| CVE-2023-41445 | 1 Phpkobo | 1 Ajaxnewsticker | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component. | |||||
| CVE-2023-41425 | 1 Wondercms | 1 Wondercms | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component. | |||||
| CVE-2023-41013 | 1 Icewarp | 1 Icewarp | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field. | |||||
| CVE-2023-40986 | 1 Webmin | 1 Webmin | 2026-07-09 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field. | |||||
| CVE-2023-40985 | 1 Webmin | 1 Webmin | 2026-07-09 | N/A | 5.4 MEDIUM |
| An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when any file is searched/replaced. | |||||
| CVE-2023-40984 | 1 Webmin | 1 Webmin | 2026-07-09 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file. | |||||
| CVE-2023-40983 | 1 Webmin | 1 Webmin | 2026-07-09 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file. | |||||
| CVE-2023-40982 | 1 Webmin | 1 Webmin | 2026-07-09 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter. | |||||
| CVE-2023-40932 | 1 Nagios | 1 Nagios Xi | 2026-07-09 | N/A | 5.4 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials. | |||||
| CVE-2023-38888 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-09 | N/A | 9.6 CRITICAL |
| Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject. | |||||
| CVE-2023-37798 | 1 Vanderbilt | 1 Redcap | 2026-07-09 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter. | |||||
