Total
47481 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-24558 | 1 Tanstack | 1 React-query-next-experimental | 2026-06-17 | N/A | 8.2 HIGH |
| TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have malicious input be returned from an endpoint. To fix this issue, please update to version 5.18.0 or later. | |||||
| CVE-2024-24556 | 1 Nearform | 1 Urql | 2026-06-17 | N/A | 7.2 HIGH |
| urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns `html` tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream. To fix this vulnerability upgrade to version 1.1.1 | |||||
| CVE-2024-24512 | 1 Pkp.sfu | 1 Open Journal Systems | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component. | |||||
| CVE-2024-24511 | 1 Pkp.sfu | 1 Open Journal Systems | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component. | |||||
| CVE-2024-24510 | 1 Alinto | 1 Sogo | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component. | |||||
| CVE-2024-24507 | 1 Act-on | 1 Act-on | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component. | |||||
| CVE-2024-24506 | 1 Limesurvey | 1 Limesurvey | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function. | |||||
| CVE-2024-24494 | 1 Remyandrade | 1 Daily Habit Tracker | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components. | |||||
| CVE-2024-24389 | 1 Xunruicms | 1 Xunruicms | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Column Name parameter. | |||||
| CVE-2024-24388 | 1 Xunruicms | 1 Xunruicms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login. | |||||
| CVE-2024-24276 | 1 Teamwire | 1 Teamwire | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components. | |||||
| CVE-2024-24275 | 2 Microsoft, Teamwire | 2 Windows, Teamwire | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. | |||||
| CVE-2024-24160 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do. | |||||
| CVE-2024-24157 | 1 Sir | 1 Gnuboard | 2026-06-17 | N/A | 6.1 MEDIUM |
| Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. | |||||
| CVE-2024-24156 | 1 Sir | 1 Gnuboard | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter. | |||||
| CVE-2024-24136 | 1 Remyandrade | 1 Math Game | 2026-06-17 | N/A | 6.1 MEDIUM |
| The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks. | |||||
| CVE-2024-24135 | 1 Remyandrade | 1 Product Inventory With Export To Excel | 2026-06-17 | N/A | 6.1 MEDIUM |
| Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks. | |||||
| CVE-2024-24134 | 1 Remyandrade | 1 Online Food Menu | 2026-06-17 | N/A | 4.8 MEDIUM |
| Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section. | |||||
| CVE-2024-24131 | 1 Superwebmailer | 1 Superwebmailer | 2026-06-17 | N/A | 6.1 MEDIUM |
| SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php. | |||||
| CVE-2024-24130 | 1 Mail2world | 1 Mail2world Webmail | 2026-06-17 | N/A | 6.1 MEDIUM |
| Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp. | |||||
