Vulnerabilities (CVE)

Filtered by CWE-79
Total 47393 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51142 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
CVE-2024-51135 2026-06-17 N/A 9.8 CRITICAL
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
CVE-2024-51122 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, CN parameters.
CVE-2024-51108 1 Anujk305 1 Medical Card Generation System 2026-06-17 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.
CVE-2024-51107 1 Anujk305 1 Medical Card Generation System 2026-06-17 N/A 4.8 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.
CVE-2024-51106 1 Anujk305 1 Medical Card Generation System 2026-06-17 N/A 4.6 MEDIUM
A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.
CVE-2024-51099 1 Phpgurukul 1 Medical Card Generation System 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter.
CVE-2024-51093 1 Snipeitapp 1 Snipe-it 2026-06-17 N/A 8.7 HIGH
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.
CVE-2024-51091 1 Seajs 1 Seajs 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package
CVE-2024-51076 1 Phpgurukul 1 Online Dj Booking Management System 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.
CVE-2024-51075 1 Phpgurukul 1 Online Dj Booking Management System 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.
CVE-2024-51055 1 Hoosk 1 Hoosk 2026-06-17 N/A 6.5 MEDIUM
An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.
CVE-2024-51054 1 Phpgurukul 1 Online Marriage Registration System 2026-06-17 N/A 4.8 MEDIUM
A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.
CVE-2024-51053 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-51032 1 Oretnom23 1 Toll Tax Management System 2026-06-17 N/A 5.4 MEDIUM
A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.
CVE-2024-51031 1 Oretnom23 1 Cab Management System 2026-06-17 N/A 5.4 MEDIUM
A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.
CVE-2024-51026 2026-06-17 N/A 5.4 MEDIUM
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.
CVE-2024-50991 1 Phpgurukul 1 User Management System 2026-06-17 N/A 4.8 MEDIUM
A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via the "fname" POST request parameter
CVE-2024-50990 1 Phpgurukul 1 Online Marriage Registration System 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.
CVE-2024-50983 1 Getflightpath 1 Flightpath 2026-06-17 N/A 5.4 MEDIUM
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.