Vulnerabilities (CVE)

Filtered by CWE-79
Total 47243 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37733 1 Tduckcloud 1 Tduck-platform 2026-07-09 N/A 6.1 MEDIUM
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
CVE-2023-37728 1 Icewarp 1 Icewarp 2026-07-09 N/A 6.1 MEDIUM
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
CVE-2023-37690 1 Phpgurukul 1 Maid Hiring Management System 2026-07-09 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
CVE-2023-37689 1 Phpgurukul 1 Maid Hiring Management System 2026-07-09 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
CVE-2023-37688 1 Phpgurukul 1 Maid Hiring Management System 2026-07-09 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
CVE-2023-37686 1 Phpgurukul 1 Online Nurse Hiring System 2026-07-09 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
CVE-2023-37685 1 Phpgurukul 1 Online Nurse Hiring System 2026-07-09 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
CVE-2023-37684 1 Phpgurukul 1 Online Nurse Hiring System 2026-07-09 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
CVE-2023-37683 1 Phpgurukul 1 Online Nurse Hiring System 2026-07-09 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
CVE-2023-36223 1 Bbs-go 1 Bbs-go 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.
CVE-2023-36222 1 Bbs-go 1 Bbs-go 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the comment parameter in the article function.
CVE-2023-36159 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
CVE-2023-36158 1 Oretnom23 1 Toll Tax Management System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.
CVE-2023-36146 1 Multilaser 2 Re170, Re170 Firmware 2026-07-09 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
CVE-2023-36081 1 Gatesair 2 Flexiva Fax 150w, Flexiva Fax 150w Firmware 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to execute arbitrary code via a crafted script to the web application dashboard.
CVE-2023-34840 1 Angular-ui-notification Project 1 Angular-ui-notification 2026-07-09 N/A 6.1 MEDIUM
angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-33438 1 Wolterskluwer 1 Teammate\+ 2026-07-09 N/A 5.4 MEDIUM
A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.
CVE-2023-31868 1 Sage 1 X3 2026-07-09 N/A 5.4 MEDIUM
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. The major one requires the user to be authenticated with a common account, he can then target an Administrator. All others endpoints need the malicious user to be authenticated as an Administrator. Therefore, the impact is diminished.
CVE-2023-31807 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
CVE-2023-31806 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.