Total
47243 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-37674 | 1 Moodle | 1 Moodle | 2026-07-09 | N/A | 5.5 MEDIUM |
| Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity. | |||||
| CVE-2024-37673 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter. | |||||
| CVE-2024-37672 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter. | |||||
| CVE-2024-37671 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter. | |||||
| CVE-2024-32409 | 1 Sem-cms | 1 Semcms | 2026-07-09 | N/A | 7.1 HIGH |
| An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. | |||||
| CVE-2024-32206 | 1 Wuzhicms | 1 Wuzhicms | 2026-07-09 | N/A | 4.6 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter. | |||||
| CVE-2024-31064 | 1 Munyweki | 1 Insurance Management System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field. | |||||
| CVE-2024-29644 | 1 Dcatadmin | 1 Dcat Admin | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box. | |||||
| CVE-2024-28722 | 2026-07-09 | N/A | 6.3 MEDIUM | ||
| Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint | |||||
| CVE-2024-26367 | 2026-07-09 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters. | |||||
| CVE-2024-24397 | 1 Stimulsoft | 1 Dashboards.js | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field. | |||||
| CVE-2024-24396 | 1 Stimulsoft | 1 Dashboard.js | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component. | |||||
| CVE-2024-22780 | 2026-07-09 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter. | |||||
| CVE-2023-51946 | 1 Actidata | 2 Actinas Sl 2u-8 Rdx, Actinas Sl 2u-8 Rdx Firmware | 2026-07-09 | N/A | 6.1 MEDIUM |
| Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML. | |||||
| CVE-2023-50470 | 1 Seacms | 1 Seacms | 2026-07-09 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2023-49494 | 1 Dedecms | 1 Dedecms | 2026-07-09 | N/A | 6.1 MEDIUM |
| DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php. | |||||
| CVE-2023-48940 | 1 Daicuo | 1 Daicuo | 2026-07-09 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2023-47324 | 1 Silverpeas | 1 Silverpeas | 2026-07-09 | N/A | 5.4 MEDIUM |
| Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature. | |||||
| CVE-2023-46952 | 1 Abocms | 1 Abo.cms | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer header. | |||||
| CVE-2023-46344 | 1 Solar-log | 2 2000 Pm\+, 2000 Pm\+ Firmware | 2026-07-09 | N/A | 5.4 MEDIUM |
| A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base. | |||||
