Total
47379 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-55492 | 1 Magicwinmail | 1 Winmail Server | 2026-06-17 | N/A | 6.1 MEDIUM |
| Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS). | |||||
| CVE-2024-55451 | 1 Ujcms | 1 Ujcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens. | |||||
| CVE-2024-55416 | 1 Thecontrolgroup | 1 Voyager | 2026-06-17 | N/A | 3.5 LOW |
| DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed. | |||||
| CVE-2024-55342 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-06-17 | N/A | 4.7 MEDIUM |
| A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability. | |||||
| CVE-2024-55341 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-06-17 | N/A | 4.7 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload. | |||||
| CVE-2024-55279 | 1 Uguu | 1 Uguu | 2026-06-17 | N/A | 6.0 MEDIUM |
| Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files. | |||||
| CVE-2024-55268 | 1 Phpgurukul | 1 Covid 19 Testing Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute arbitrary code via the regmobilenumber parameter. | |||||
| CVE-2024-55239 | 1 Portabilis | 1 I-educar | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter. | |||||
| CVE-2024-55228 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.0 CRITICAL |
| A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-55227 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.0 CRITICAL |
| A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-55226 | 1 Dani-garcia | 1 Vaultwarden | 2026-06-17 | N/A | 5.4 MEDIUM |
| Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs. | |||||
| CVE-2024-55224 | 1 Dani-garcia | 1 Vaultwarden | 2026-06-17 | N/A | 9.6 CRITICAL |
| An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message. | |||||
| CVE-2024-55218 | 1 Icewarp | 1 Icewarp | 2026-06-17 | N/A | 6.1 MEDIUM |
| IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter. | |||||
| CVE-2024-55199 | 1 Celk | 1 Celk Saude | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser. | |||||
| CVE-2024-55100 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter. | |||||
| CVE-2024-55093 | 1 Phpipam | 1 Phpipam | 2026-06-17 | N/A | 5.4 MEDIUM |
| phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts. | |||||
| CVE-2024-55074 | 1 Grocy Project | 1 Grocy | 2026-06-17 | N/A | 8.8 HIGH |
| The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370. | |||||
| CVE-2024-55064 | 1 Easyvirt | 1 Dc Netscope | 2026-06-17 | N/A | 5.4 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter. | |||||
| CVE-2024-55060 | 1 Rafed-system | 1 Rafed Cms Website | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-55059 | 1 Phpgurukul | 1 Online Birth Certificate System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php. | |||||
