Total
47397 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-44920 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter. | |||||
| CVE-2024-44919 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter. | |||||
| CVE-2024-44918 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 3.5 LOW |
| A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-44872 | 1 Mozilo | 1 Mozilocms | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |||||
| CVE-2024-44851 | 1 Perfexcrm | 1 Perfex Crm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter. | |||||
| CVE-2024-44837 | 1 Deathbreak | 1 Drug | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user parameter. | |||||
| CVE-2024-44820 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables. | |||||
| CVE-2024-44819 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component. | |||||
| CVE-2024-44818 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component. | |||||
| CVE-2024-44798 | 1 Anujk305 | 1 Bus Pass Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters. | |||||
| CVE-2024-44771 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function. | |||||
| CVE-2024-44731 | 2026-06-17 | N/A | 4.7 MEDIUM | ||
| Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections. | |||||
| CVE-2024-44728 | 1 Angeljudesuarez | 1 Event Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php. | |||||
| CVE-2024-44717 | 1 Dedebiz | 1 Dedebiz | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-44716 | 1 Dedebiz | 1 Dedebiz | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-44684 | 1 Tpmecms | 1 Tpmecms | 2026-06-17 | N/A | 6.1 MEDIUM |
| TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields. | |||||
| CVE-2024-44683 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. | |||||
| CVE-2024-44682 | 1 Shopxo | 1 Shopxo | 2026-06-17 | N/A | 6.1 MEDIUM |
| ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters. | |||||
| CVE-2024-44676 | 1 Eladmin | 1 Eladmin | 2026-06-17 | N/A | 4.8 MEDIUM |
| eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java. | |||||
| CVE-2024-44661 | 1 Phpgurukul | 1 Online Shopping Portal | 2026-06-17 | N/A | 5.4 MEDIUM |
| PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | |||||
