Total
47394 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48703 | 1 Anujk305 | 1 Medical Card Generation System | 2026-06-17 | N/A | 4.8 MEDIUM |
| PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter. | |||||
| CVE-2024-48702 | 1 Phpgurukul | 1 Old Age Home Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter. | |||||
| CVE-2024-48662 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component. | |||||
| CVE-2024-48656 | 1 Angeljudesuarez | 1 Student Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code. | |||||
| CVE-2024-48654 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component. | |||||
| CVE-2024-48652 | 1 Tuzitio | 1 Camaleon Cms | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field. | |||||
| CVE-2024-48648 | 1 Sage | 1 Sage Frp 1000 | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding. | |||||
| CVE-2024-48624 | 1 Domainmod | 1 Domainmod | 2026-06-17 | N/A | 5.3 MEDIUM |
| In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability. | |||||
| CVE-2024-48623 | 1 Domainmod | 1 Domainmod | 2026-06-17 | N/A | 5.3 MEDIUM |
| In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS). | |||||
| CVE-2024-48622 | 1 Domainmod | 1 Domainmod | 2026-06-17 | N/A | 6.6 MEDIUM |
| A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter. | |||||
| CVE-2024-48591 | 1 Inflectra | 1 Spirateam | 2026-06-17 | N/A | 6.1 MEDIUM |
| Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing. | |||||
| CVE-2024-48589 | 2026-06-17 | N/A | 6.3 MEDIUM | ||
| Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php | |||||
| CVE-2024-48569 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/ | |||||
| CVE-2024-48536 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request. | |||||
| CVE-2024-48535 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |||||
| CVE-2024-48534 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |||||
| CVE-2024-48531 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |||||
| CVE-2024-48461 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field. | |||||
| CVE-2024-48448 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page. | |||||
| CVE-2024-48415 | 1 Razormist | 1 Loan Management System | 2026-06-17 | N/A | 5.0 MEDIUM |
| itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page. | |||||
