Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24115 1 Cotonti 1 Cotonti Siena 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-24097 1 Code-projects 1 Scholars Tracking System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.
CVE-2024-24062 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
CVE-2024-24061 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
CVE-2024-24060 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
CVE-2024-24059 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.
CVE-2024-24050 1 Remyandrade 1 Workout Journal App 2026-06-17 N/A 4.7 MEDIUM
Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.
CVE-2024-24041 1 Remyandrade 1 Travel Journal Using Php And Mysql With Source Code 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
CVE-2024-24035 1 Setorinformatica 1 S.i.l. 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.
CVE-2024-23998 1 Goanother 1 Another Redis Desktop Manager 2026-06-17 N/A 9.6 CRITICAL
goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.
CVE-2024-23997 1 Lukasbach 1 Yana 2026-06-17 N/A 9.6 CRITICAL
Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.
CVE-2024-23995 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.
CVE-2024-23941 1 Group-office 1 Group Office 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
CVE-2024-23906 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration during an authenticated Operator's session. This issue affects: Controller 6000 and Controller 7000 9.10 prior to vCR9.10.240816a (distributed in 9.10.1530 (MR2)), 9.00 prior to vCR9.00.240816a (distributed in 9.00.2168 (MR4)), 8.90 prior to vCR8.90.240816a (distributed in 8.90.2155 (MR5)), 8.80 prior to vCR8.80.240816b (distributed in 8.80.1938 (MR6)), all versions of 8.70 and prior.
CVE-2024-23905 1 Jenkins 1 Red Hat Dependency Analytics 2026-06-17 N/A 5.4 MEDIUM
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
CVE-2024-23896 1 Ajaysharma 1 Cups Easy 2026-06-17 N/A 8.2 HIGH
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stock.php, in the batchno parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
CVE-2024-23895 1 Ajaysharma 1 Cups Easy 2026-06-17 N/A 8.2 HIGH
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/locationcreate.php, in the locationid parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
CVE-2024-23894 1 Ajaysharma 1 Cups Easy 2026-06-17 N/A 8.2 HIGH
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancecreate.php, in the issuancedate parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
CVE-2024-23893 1 Ajaysharma 1 Cups Easy 2026-06-17 N/A 8.2 HIGH
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/costcentermodify.php, in the costcenterid parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
CVE-2024-23892 1 Ajaysharma 1 Cups Easy 2026-06-17 N/A 8.2 HIGH
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/costcentercreate.php, in the costcenterid parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.