Total
47376 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57427 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 6.1 MEDIUM |
| PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks. | |||||
| CVE-2024-57423 | 1 Vishalmathur | 1 Cloudclassroom-php Project | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function. | |||||
| CVE-2024-57409 | 1 Beian.miit | 1 Cool-admin-java | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field. | |||||
| CVE-2024-57386 | 1 Wallosapp | 1 Wallos | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function. | |||||
| CVE-2024-57372 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters | |||||
| CVE-2024-57348 | 1 Pecanproject | 1 Pecan | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary code via the crafted payload to the hostname, sitegroupid, lat, lon and sitename parameters. | |||||
| CVE-2024-57329 | 1 Hortusfox | 1 Hortusfox | 2026-06-17 | N/A | 5.4 MEDIUM |
| HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads. | |||||
| CVE-2024-57326 | 1 Online Pizza Delivery System Project | 1 Online Pizza Delivery System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter. | |||||
| CVE-2024-57279 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifically in the /setup/index.php endpoint via the returnto parameter. This vulnerability arises due to improper sanitization of user-supplied input, allowing an attacker to inject malicious JavaScript. | |||||
| CVE-2024-57278 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vulnerability is caused by improper input sanitization of the query parameter, allowing an attacker to inject malicious JavaScript payloads. When a victim accesses a crafted URL containing the malicious input, the script executes in the victim's browser context. | |||||
| CVE-2024-57277 | 2026-06-17 | N/A | 5.7 MEDIUM | ||
| InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload. | |||||
| CVE-2024-57272 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2024-57240 | 1 Apryse | 1 Webviewer | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file. | |||||
| CVE-2024-57237 | 2026-06-17 | N/A | 6.3 MEDIUM | ||
| Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute injected JavaScript code. | |||||
| CVE-2024-57175 | 1 Phpgurukul | 1 Online Birth Certificate System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php. | |||||
| CVE-2024-57097 | 1 Classcms | 1 Classcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php. | |||||
| CVE-2024-57033 | 1 Wegia | 1 Wegia | 2026-06-17 | N/A | 6.1 MEDIUM |
| WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php. | |||||
| CVE-2024-57030 | 1 Wegia | 1 Wegia | 2026-06-17 | N/A | 8.1 HIGH |
| Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter. | |||||
| CVE-2024-57026 | 1 Tawk | 1 Tawk.to | 2026-06-17 | N/A | 6.1 MEDIUM |
| TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution. | |||||
| CVE-2024-56998 | 1 Phpgurukul | 1 Hospital Management System | 2026-06-17 | N/A | 4.2 MEDIUM |
| PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address. | |||||
