Total
47397 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-42791 | 1 Lopalopa | 1 Music Management System | 2026-06-17 | N/A | 8.8 HIGH |
| A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre. | |||||
| CVE-2024-42790 | 1 Lopalopa | 1 Music Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter. | |||||
| CVE-2024-42789 | 1 Lopalopa | 1 Music Management System | 2026-06-17 | N/A | 6.3 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter. | |||||
| CVE-2024-42788 | 1 Lopalopa | 1 Music Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "artist" parameter fields. | |||||
| CVE-2024-42787 | 1 Lopalopa | 1 Music Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "description" parameter fields. | |||||
| CVE-2024-42771 | 1 Jayesh | 1 Hotel Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter. | |||||
| CVE-2024-42770 | 1 Jayesh | 1 Hotel Management System | 2026-06-17 | N/A | 4.7 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter. | |||||
| CVE-2024-42769 | 1 Jayesh | 1 Hotel Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters. | |||||
| CVE-2024-42763 | 1 Kjayvik | 1 Bus Ticket Reservation System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the "bookingdate" parameter. | |||||
| CVE-2024-42762 | 1 Kjayvik | 1 Bus Ticket Reservation System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the Name, Phone, and Email parameter fields. | |||||
| CVE-2024-42761 | 1 Kjayvik | 1 Bus Ticket Reservation System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via scheduleDurationPHP parameter. | |||||
| CVE-2024-42758 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A malicious attacker can input XSS payloads for example when creating or editing existing page, to trigger the XSS on Dokuwiki, which is then stored in .txt file (due to nature of how Dokuwiki is designed), which presents stored XSS. | |||||
| CVE-2024-42749 | 1 Altocms | 1 Alto Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted script. | |||||
| CVE-2024-42699 | 1 Alkacon | 1 Opencms | 2026-06-17 | N/A | 6.5 MEDIUM |
| Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field | |||||
| CVE-2024-42697 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function. | |||||
| CVE-2024-42678 | 1 Cysoft168 | 1 Super Easy Enterprise Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component. | |||||
| CVE-2024-42671 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities. | |||||
| CVE-2024-42560 | 1 Varunsardana004 | 1 Blood Bank And Donation Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details parameter. | |||||
| CVE-2024-42550 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-42515 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry. | |||||
