Vulnerabilities (CVE)

Filtered by CWE-79
Total 47243 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37674 1 Moodle 1 Moodle 2026-07-09 N/A 5.5 MEDIUM
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
CVE-2024-37673 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.
CVE-2024-37672 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.
CVE-2024-37671 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter.
CVE-2024-32409 1 Sem-cms 1 Semcms 2026-07-09 N/A 7.1 HIGH
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2024-32206 1 Wuzhicms 1 Wuzhicms 2026-07-09 N/A 4.6 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.
CVE-2024-31064 1 Munyweki 1 Insurance Management System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.
CVE-2024-29644 1 Dcatadmin 1 Dcat Admin 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.
CVE-2024-28722 2026-07-09 N/A 6.3 MEDIUM
Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
CVE-2024-26367 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.
CVE-2024-24397 1 Stimulsoft 1 Dashboards.js 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.
CVE-2024-24396 1 Stimulsoft 1 Dashboard.js 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
CVE-2024-22780 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.
CVE-2023-51946 1 Actidata 2 Actinas Sl 2u-8 Rdx, Actinas Sl 2u-8 Rdx Firmware 2026-07-09 N/A 6.1 MEDIUM
Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.
CVE-2023-50470 1 Seacms 1 Seacms 2026-07-09 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-49494 1 Dedecms 1 Dedecms 2026-07-09 N/A 6.1 MEDIUM
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
CVE-2023-48940 1 Daicuo 1 Daicuo 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-47324 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 5.4 MEDIUM
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
CVE-2023-46952 1 Abocms 1 Abo.cms 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer header.
CVE-2023-46344 1 Solar-log 2 2000 Pm\+, 2000 Pm\+ Firmware 2026-07-09 N/A 5.4 MEDIUM
A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.