Total
47389 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-53617 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. | |||||
| CVE-2024-53599 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-53569 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter. | |||||
| CVE-2024-53568 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter. | |||||
| CVE-2024-53563 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |||||
| CVE-2024-53556 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a crafted link to /login?next= in the login page URL. | |||||
| CVE-2024-53471 | 1 Wegia | 1 Wegia | 2026-06-17 | N/A | 6.1 MEDIUM |
| Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter. | |||||
| CVE-2024-53470 | 1 Wegia | 1 Wegia | 2026-06-17 | N/A | 6.1 MEDIUM |
| Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter. | |||||
| CVE-2024-53459 | 1 Sysax | 1 Multi Server | 2026-06-17 | N/A | 5.4 MEDIUM |
| Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter. | |||||
| CVE-2024-53457 | 1 Librenms | 1 Librenms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter. | |||||
| CVE-2024-53442 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component. | |||||
| CVE-2024-53408 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability. | |||||
| CVE-2024-53388 | 1 Mavo | 1 Mavo | 2026-06-17 | N/A | 8.8 HIGH |
| A DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML element. | |||||
| CVE-2024-53387 | 1 Umeditor Project | 1 Umeditor | 2026-06-17 | N/A | 8.8 HIGH |
| A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element. | |||||
| CVE-2024-53386 | 1 Piqnt | 1 Stage.js | 2026-06-17 | N/A | 4.9 MEDIUM |
| Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | |||||
| CVE-2024-53384 | 1 Egoist | 1 Tsup | 2026-06-17 | N/A | 5.1 MEDIUM |
| A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components | |||||
| CVE-2024-53382 | 1 Prismjs | 1 Prism | 2026-06-17 | N/A | 4.9 MEDIUM |
| Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | |||||
| CVE-2024-53307 | 1 Evisions | 1 Maps | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in the /mw/ endpoint of Evisions MAPS v6.10.2.267 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |||||
| CVE-2024-53288 | 1 Synology | 1 Router Manager | 2026-06-17 | N/A | 5.9 MEDIUM |
| Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2024-53287 | 1 Synology | 1 Router Manager | 2026-06-17 | N/A | 5.9 MEDIUM |
| Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |||||
