Total
47393 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-51142 | 1 Chamilo | 1 Chamilo Lms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file. | |||||
| CVE-2024-51135 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities. | |||||
| CVE-2024-51122 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, CN parameters. | |||||
| CVE-2024-51108 | 1 Anujk305 | 1 Medical Card Generation System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters. | |||||
| CVE-2024-51107 | 1 Anujk305 | 1 Medical Card Generation System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters. | |||||
| CVE-2024-51106 | 1 Anujk305 | 1 Medical Card Generation System | 2026-06-17 | N/A | 4.6 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter. | |||||
| CVE-2024-51099 | 1 Phpgurukul | 1 Medical Card Generation System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter. | |||||
| CVE-2024-51093 | 1 Snipeitapp | 1 Snipe-it | 2026-06-17 | N/A | 8.7 HIGH |
| Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system. | |||||
| CVE-2024-51091 | 1 Seajs | 1 Seajs | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package | |||||
| CVE-2024-51076 | 1 Phpgurukul | 1 Online Dj Booking Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter. | |||||
| CVE-2024-51075 | 1 Phpgurukul | 1 Online Dj Booking Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter. | |||||
| CVE-2024-51055 | 1 Hoosk | 1 Hoosk | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component. | |||||
| CVE-2024-51054 | 1 Phpgurukul | 1 Online Marriage Registration System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter. | |||||
| CVE-2024-51053 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-51032 | 1 Oretnom23 | 1 Toll Tax Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field. | |||||
| CVE-2024-51031 | 1 Oretnom23 | 1 Cab Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields. | |||||
| CVE-2024-51026 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field. | |||||
| CVE-2024-50991 | 1 Phpgurukul | 1 User Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via the "fname" POST request parameter | |||||
| CVE-2024-50990 | 1 Phpgurukul | 1 Online Marriage Registration System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter. | |||||
| CVE-2024-50983 | 1 Getflightpath | 1 Flightpath | 2026-06-17 | N/A | 5.4 MEDIUM |
| FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections. | |||||
