Total
47379 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-55059 | 1 Phpgurukul | 1 Online Birth Certificate System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php. | |||||
| CVE-2024-55056 | 1 Phpgurukul | 1 Online Birth Certificate System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field. | |||||
| CVE-2024-55040 | 1 Sensaphone | 2 Web600, Web600 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters. | |||||
| CVE-2024-55029 | 1 Nasa | 1 Fprime | 2026-06-17 | N/A | 6.1 MEDIUM |
| NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | |||||
| CVE-2024-55009 | 1 Datax | 1 Autobib | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter. | |||||
| CVE-2024-55000 | 1 Mayurik | 1 House Rental Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php. | |||||
| CVE-2024-54959 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 6.1 MEDIUM |
| Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS). | |||||
| CVE-2024-54958 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 6.1 MEDIUM |
| Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page. | |||||
| CVE-2024-54951 | 1 Monicahq | 1 Monica | 2026-06-17 | N/A | 5.4 MEDIUM |
| Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS. | |||||
| CVE-2024-54936 | 1 Lopalopa | 1 E-learning Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter. | |||||
| CVE-2024-54935 | 1 Lopalopa | 1 E-learning Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter. | |||||
| CVE-2024-54919 | 1 Lopalopa | 1 E-learning Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter. | |||||
| CVE-2024-54853 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser. | |||||
| CVE-2024-54795 | 1 Eng | 1 Spagobi | 2026-06-17 | N/A | 5.4 MEDIUM |
| SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. | |||||
| CVE-2024-54779 | 1 Netgate | 2 Pfsense Ce, Pfsense Plus | 2026-06-17 | N/A | 5.4 MEDIUM |
| Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php. | |||||
| CVE-2024-54775 | 1 Dcatadmin | 1 Dcat Admin | 2026-06-17 | N/A | 4.8 MEDIUM |
| Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /admin/auth/extensions. | |||||
| CVE-2024-54774 | 1 Dcatadmin | 1 Dcat Admin | 2026-06-17 | N/A | 4.8 MEDIUM |
| Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create. | |||||
| CVE-2024-54687 | 1 Vtiger | 1 Vtiger Crm | 2026-06-17 | N/A | 6.1 MEDIUM |
| Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php. | |||||
| CVE-2024-54675 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow. | |||||
| CVE-2024-54674 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format. | |||||
