Vulnerabilities (CVE)

Filtered by CWE-79
Total 47395 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46475 2026-06-17 N/A 4.8 MEDIUM
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-46470 1 Codeastro 1 Membership Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.
CVE-2024-46453 1 Honeywell 2 Iq3xcite, Iq3xcite Firmware 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-46410 1 Publiccms 1 Publiccms 2026-06-17 N/A 4.8 MEDIUM
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature
CVE-2024-46409 1 Seeddms 1 Seeddms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.
CVE-2024-46372 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.1 MEDIUM
DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.
CVE-2024-46367 1 Webkul 1 Krayin Crm 2026-06-17 N/A 9.6 CRITICAL
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
CVE-2024-46336 1 Kashipara 1 School Management System 2026-06-17 N/A 6.1 MEDIUM
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
CVE-2024-46335 1 Phpgurukul 1 Complaint Management System 2026-06-17 N/A 4.6 MEDIUM
PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.
CVE-2024-46334 1 Kashipara 1 School Management System 2026-06-17 N/A 6.1 MEDIUM
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.
CVE-2024-46333 1 Piwigo 1 Piwigo 2026-06-17 N/A 4.8 MEDIUM
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.
CVE-2024-46300 1 Angeljudesuarez 1 Placement Management System 2026-06-17 N/A 6.1 MEDIUM
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
CVE-2024-46278 1 Sismics 1 Teedy 2026-06-17 N/A 8.4 HIGH
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
CVE-2024-46241 1 Phpgurukul 1 Dairy Farm Shop Management System 2026-06-17 N/A 5.9 MEDIUM
PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.
CVE-2024-46240 1 O-dyn 1 Collabtive 2026-06-17 N/A 4.8 MEDIUM
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
CVE-2024-46239 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.9 MEDIUM
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
CVE-2024-46238 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.9 MEDIUM
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
CVE-2024-46237 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
CVE-2024-46236 1 Codeastro 1 Membership Management System 2026-06-17 N/A 5.4 MEDIUM
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
CVE-2024-46226 1 Helpdeskz 1 Helpdeskz 2026-06-17 N/A 4.8 MEDIUM
A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.