Total
47317 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-29594 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure. | |||||
| CVE-2025-29573 | 1 Jupo | 1 Mezzanine | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module. | |||||
| CVE-2025-29568 | 1 Code-projects | 1 Online Class And Exam Scheduling System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS). | |||||
| CVE-2025-29526 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter. | |||||
| CVE-2025-29471 | 1 Nagios | 1 Log Server | 2026-06-17 | N/A | 8.3 HIGH |
| Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field. | |||||
| CVE-2025-29429 | 1 Fabian | 1 Online Class And Exam Scheduling System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters. | |||||
| CVE-2025-29412 | 1 Martmbithi | 1 Ibanking | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |||||
| CVE-2025-29410 | 1 Kishanlal | 1 Hospital Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter. | |||||
| CVE-2025-29389 | 1 Pbootcms | 1 Pbootcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2. | |||||
| CVE-2025-29322 | 2026-06-17 | N/A | 4.6 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary code via a crafted payload to the "Connection Name" in the New Connection and Rename Connection pages. | |||||
| CVE-2025-29280 | 1 Perfree | 1 Perfreeblog | 2026-06-17 | N/A | 4.8 MEDIUM |
| Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code. | |||||
| CVE-2025-29231 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters. | |||||
| CVE-2025-29192 | 1 Flowiseai | 1 Flowise | 2026-06-17 | N/A | 8.2 HIGH |
| Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log. | |||||
| CVE-2025-29156 | 1 Smartbear | 1 Swagger Petstore | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet | |||||
| CVE-2025-29152 | 1 Lemeconsultoria | 1 Galera | 2026-06-17 | N/A | 7.6 HIGH |
| Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Registration, Hierarchical Level Registration, Decision Level Registration, Perspective Registration, Company Group Registration, Company Registration, News Registration, Employee Editing, Goal Team Registration, Learning Resource Type Registration, Learning Resource Family Registration, Learning Resource Supplier Registration, and Cycle Maintenance. | |||||
| CVE-2025-29094 | 1 Motivian | 1 Content Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components. | |||||
| CVE-2025-29049 | 2026-06-17 | N/A | 6.3 MEDIUM | ||
| Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function. | |||||
| CVE-2025-29018 | 1 Codeastro | 1 Internet Banking System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0. | |||||
| CVE-2025-29015 | 1 Codeastro | 1 Internet Banking System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php. | |||||
| CVE-2025-29014 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu allows Reflected XSS. This issue affects FoodMenu: from n/a through 1.20. | |||||
