Vulnerabilities (CVE)

Filtered by CWE-79
Total 47394 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48703 1 Anujk305 1 Medical Card Generation System 2026-06-17 N/A 4.8 MEDIUM
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.
CVE-2024-48702 1 Phpgurukul 1 Old Age Home Management System 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-48662 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component.
CVE-2024-48656 1 Angeljudesuarez 1 Student Management System 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
CVE-2024-48654 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component.
CVE-2024-48652 1 Tuzitio 1 Camaleon Cms 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.
CVE-2024-48648 1 Sage 1 Sage Frp 1000 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.
CVE-2024-48624 1 Domainmod 1 Domainmod 2026-06-17 N/A 5.3 MEDIUM
In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.
CVE-2024-48623 1 Domainmod 1 Domainmod 2026-06-17 N/A 5.3 MEDIUM
In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).
CVE-2024-48622 1 Domainmod 1 Domainmod 2026-06-17 N/A 6.6 MEDIUM
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.
CVE-2024-48591 1 Inflectra 1 Spirateam 2026-06-17 N/A 6.1 MEDIUM
Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.
CVE-2024-48589 2026-06-17 N/A 6.3 MEDIUM
Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php
CVE-2024-48569 2026-06-17 N/A 5.4 MEDIUM
Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/
CVE-2024-48536 1 Esoftplanner 1 Esoft Planner 2026-06-17 N/A 7.5 HIGH
Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.
CVE-2024-48535 1 Esoftplanner 1 Esoft Planner 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
CVE-2024-48534 1 Esoftplanner 1 Esoft Planner 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-48531 1 Esoftplanner 1 Esoft Planner 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-48461 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.
CVE-2024-48448 2026-06-17 N/A 6.1 MEDIUM
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page.
CVE-2024-48415 1 Razormist 1 Loan Management System 2026-06-17 N/A 5.0 MEDIUM
itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.