Total
47475 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-36624 | 1 Zulip | 1 Zulip | 2026-06-17 | N/A | 5.4 MEDIUM |
| Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js. | |||||
| CVE-2024-36599 | 1 Aegon | 1 Life Insurance Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php. | |||||
| CVE-2024-36577 | 2026-06-17 | N/A | 8.3 HIGH | ||
| apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty. | |||||
| CVE-2024-36498 | 2026-06-17 | N/A | 4.7 MEDIUM | ||
| Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre The stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser. Version 7.40 implemented a fix, but it could be bypassed via URL-encoding the Javascript payload again. | |||||
| CVE-2024-36494 | 2026-06-17 | N/A | 4.7 MEDIUM | ||
| Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts. | |||||
| CVE-2024-36453 | 1 Webmin | 2 Usermin, Webmin | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed. | |||||
| CVE-2024-36450 | 1 Webmin | 1 Webmin | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted. | |||||
| CVE-2024-36423 | 1 Flowiseai | 1 Flowise | 2026-06-17 | N/A | 6.1 MEDIUM |
| Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/public-chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascript into the user sessions, allowing the attacker to steal information, create false popups, or even redirect the user to other websites without interaction. If the chatflow ID is not found, its value is reflected in the 404 page, which has type text/html. This allows an attacker to attach arbitrary scripts to the page, allowing an attacker to steal sensitive information. This XSS may be chained with the path injection to allow an attacker without direct access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available. | |||||
| CVE-2024-36422 | 1 Flowiseai | 1 Flowise | 2026-06-17 | N/A | 6.1 MEDIUM |
| Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `api/v1/chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascript into the user sessions, allowing the attacker to steal information, create false popups, or even redirect the user to other websites without interaction. If the chatflow ID is not found, its value is reflected in the 404 page, which has type text/html. This allows an attacker to attach arbitrary scripts to the page, allowing an attacker to steal sensitive information. This XSS may be chained with the path injection to allow an attacker without direct access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available. | |||||
| CVE-2024-36417 | 1 Salesagility | 1 Suitecrm | 2026-06-17 | N/A | 5.7 MEDIUM |
| SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unverified IFrame can be added some some inputs, which could allow for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |||||
| CVE-2024-36413 | 1 Salesagility | 1 Suitecrm | 2026-06-17 | N/A | 8.9 HIGH |
| SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |||||
| CVE-2024-36397 | 1 Vantiva | 2 Mediaaccess Dga2232, Mediaaccess Dga2232 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-36392 | 2 Canonical, Milesight | 2 Ubuntu Linux, Devicehub | 2026-06-17 | N/A | 6.1 MEDIUM |
| MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-36384 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages. | |||||
| CVE-2024-36374 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible | |||||
| CVE-2024-36373 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible | |||||
| CVE-2024-36372 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible | |||||
| CVE-2024-36371 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible | |||||
| CVE-2024-36370 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible | |||||
| CVE-2024-36369 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible | |||||
