Total
47393 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-49211 | 1 Archerirm | 1 Archer | 2026-06-17 | N/A | 5.2 MEDIUM |
| Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application. | |||||
| CVE-2024-49210 | 1 Archerirm | 1 Archer | 2026-06-17 | N/A | 5.2 MEDIUM |
| Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application. | |||||
| CVE-2024-49053 | 1 Microsoft | 1 Dynamics 365 Sales | 2026-06-17 | N/A | 7.6 HIGH |
| Microsoft Dynamics 365 Sales Spoofing Vulnerability | |||||
| CVE-2024-49038 | 1 Microsoft | 1 Copilot Studio | 2026-06-17 | N/A | 9.3 CRITICAL |
| Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | |||||
| CVE-2024-48937 | 1 Znuny | 1 Znuny | 2026-06-17 | N/A | 6.1 MEDIUM |
| Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed. | |||||
| CVE-2024-48933 | 1 Lemonldap-ng | 1 Lemonldap\ | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters. | |||||
| CVE-2024-48927 | 1 Umbraco | 1 Umbraco Cms | 2026-06-17 | N/A | 4.6 MEDIUM |
| Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue. As a workaround, derver-side file validation is available to strip script tags from file's content during the file upload process. | |||||
| CVE-2024-48906 | 1 Sematell | 1 Replyone | 2026-06-17 | N/A | 6.1 MEDIUM |
| Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name. | |||||
| CVE-2024-48893 | 1 Fortinet | 1 Fortisoar | 2026-06-17 | N/A | 6.8 MEDIUM |
| An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook. | |||||
| CVE-2024-48870 | 2 Sharp, Toshibatec | 640 Bp-30c25, Bp-30c25 Firmware, Bp-30c25t and 637 more | 2026-06-17 | N/A | 6.2 MEDIUM |
| Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. | |||||
| CVE-2024-48821 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component. | |||||
| CVE-2024-48807 | 1 Phpgurukul | 1 Doctor Appointment Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter. | |||||
| CVE-2024-48761 | 1 Celk | 1 Celk Saude | 2026-06-17 | N/A | 8.8 HIGH |
| Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter. | |||||
| CVE-2024-48743 | 1 Telestream | 1 Sentry | 2026-06-17 | N/A | 6.5 MEDIUM |
| Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter. | |||||
| CVE-2024-48709 | 1 Codeastro | 1 Membership Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php | |||||
| CVE-2024-48708 | 1 O-dyn | 1 Collabtive | 2026-06-17 | N/A | 5.4 MEDIUM |
| Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser. | |||||
| CVE-2024-48707 | 1 O-dyn | 1 Collabtive | 2026-06-17 | N/A | 5.4 MEDIUM |
| Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file. | |||||
| CVE-2024-48706 | 1 O-dyn | 1 Collabtive | 2026-06-17 | N/A | 5.4 MEDIUM |
| Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively. | |||||
| CVE-2024-48704 | 1 Phpgurukul | 1 Medical Card Generation System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes. | |||||
| CVE-2024-48703 | 1 Anujk305 | 1 Medical Card Generation System | 2026-06-17 | N/A | 4.8 MEDIUM |
| PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter. | |||||
