Vulnerabilities (CVE)

Filtered by CWE-79
Total 28743 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28683 2024-08-15 N/A 6.1 MEDIUM
DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.
CVE-2024-28680 2024-08-15 N/A 6.1 MEDIUM
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php.
CVE-2024-25895 2024-08-15 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php
CVE-2024-24506 2024-08-15 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.
CVE-2024-38211 1 Microsoft 1 Dynamics 365 2024-08-15 N/A 8.2 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-7343 1 Baidu 1 Ueditor 2024-08-15 4.0 MEDIUM 6.1 MEDIUM
A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273274 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-7678 1 Oretnom23 1 Car Driving School Management System 2024-08-15 4.0 MEDIUM 6.1 MEDIUM
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_package. The manipulation of the argument name/description/training_duration leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7677 1 Oretnom23 1 Car Driving School Management System 2024-08-15 4.0 MEDIUM 6.1 MEDIUM
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7660 1 Rems 1 File Manager App 2024-08-15 4.0 MEDIUM 6.1 MEDIUM
A vulnerability has been found in SourceCodester File Manager App 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Add File Handler. The manipulation of the argument File Title/Uploaded By leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7657 1 Gilacms 1 Gila Cms 2024-08-15 4.0 MEDIUM 5.4 MEDIUM
A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-7749 1 Rems 1 Accounts Manager App 2024-08-15 4.0 MEDIUM 5.4 MEDIUM
A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The manipulation of the argument account_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-6050 1 Sokrates 1 Sowa Opac 2024-08-15 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.
CVE-2024-38953 1 Phpok 1 Phpok 2024-08-15 N/A 6.1 MEDIUM
phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.
CVE-2024-33993 1 Janobe 1 School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.
CVE-2024-33992 1 Janobe 1 School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.
CVE-2024-33991 1 Janobe 1 School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.
CVE-2024-33990 1 Janobe 1 School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.
CVE-2024-33989 1 Janobe 1 School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in 'port/event_print.php'.
CVE-2024-33985 1 Janobe 2 School Attendence Monitoring System, School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.
CVE-2024-33986 1 Janobe 2 School Attendence Monitoring System, School Event Management System 2024-08-15 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.