Total
47475 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-31063 | 1 Munyweki | 1 Insurance Management System | 2026-06-17 | N/A | 6.4 MEDIUM |
| Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field. | |||||
| CVE-2024-31061 | 1 Munyweki | 1 Insurance Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field. | |||||
| CVE-2024-31013 | 1 Emlog | 1 Emlog | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter. | |||||
| CVE-2024-30989 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter. | |||||
| CVE-2024-30988 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 6.8 MEDIUM |
| Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar. | |||||
| CVE-2024-30987 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 6.8 MEDIUM |
| Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters. | |||||
| CVE-2024-30986 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter. | |||||
| CVE-2024-30979 | 1 Phpgurukul | 1 Cyber Cafe Management System | 2026-06-17 | N/A | 5.9 MEDIUM |
| Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php. | |||||
| CVE-2024-30953 | 1 Htmly | 1 Htmly | 2026-06-17 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link Name parameter of Menu Editor module. | |||||
| CVE-2024-30952 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability in PESCMS-TEAM v2.3.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the domain input field under /youdoamin/?g=Team&m=Setting&a=action. | |||||
| CVE-2024-30951 | 1 Fudforum | 1 Fudforum | 2026-06-17 | N/A | 6.1 MEDIUM |
| FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php. | |||||
| CVE-2024-30950 | 1 Fudforum | 1 Fudforum | 2026-06-17 | N/A | 3.5 LOW |
| A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php. | |||||
| CVE-2024-30931 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Stored Cross Site Scripting vulnerability in Emby Media Server Emby Media Server 4.8.3.0 allows a remote attacker to escalate privileges via the notifications.html component. | |||||
| CVE-2024-30929 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 8.0 HIGH |
| Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php | |||||
| CVE-2024-30927 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 6.3 MEDIUM |
| Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component. | |||||
| CVE-2024-30926 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 4.6 MEDIUM |
| Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component. | |||||
| CVE-2024-30925 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 6.5 MEDIUM |
| Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component. | |||||
| CVE-2024-30921 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component. | |||||
| CVE-2024-30920 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 7.4 HIGH |
| Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component. | |||||
| CVE-2024-30890 | 1 Ed01-cms Project | 1 Ed01-cms | 2026-06-17 | N/A | 4.7 MEDIUM |
| Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. | |||||
