Total
45311 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-25825 | 1 Emlog | 1 Emlog | 2026-07-05 | N/A | 7.1 HIGH |
| A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section. | |||||
| CVE-2025-25823 | 1 Emlog | 1 Emlog | 2026-07-05 | N/A | 7.3 HIGH |
| A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php. | |||||
| CVE-2025-25818 | 1 Emlog | 1 Emlog | 2026-07-05 | N/A | 5.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php. | |||||
| CVE-2025-25612 | 2026-07-05 | N/A | 7.1 HIGH | ||
| FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser. | |||||
| CVE-2024-57529 | 1 Jeppesen | 1 Jetplanner | 2026-07-05 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code. | |||||
| CVE-2024-57370 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter. | |||||
| CVE-2024-57273 | 1 Netgate | 2 Pfsense Ce, Pfsense Plus | 2026-07-05 | N/A | 5.4 MEDIUM |
| Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key. | |||||
| CVE-2024-57041 | 1 Nodebb | 1 Nodebb | 2026-07-05 | N/A | 4.6 MEDIUM |
| A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile. | |||||
| CVE-2024-54998 | 1 Monicahq | 1 Monica | 2026-07-05 | N/A | 5.4 MEDIUM |
| MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create. | |||||
| CVE-2024-54996 | 1 Monicahq | 1 Monica | 2026-07-05 | N/A | 8.8 HIGH |
| MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create. | |||||
| CVE-2024-54994 | 1 Monicahq | 1 Monica | 2026-07-05 | N/A | 6.5 MEDIUM |
| MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature. | |||||
| CVE-2024-53481 | 1 Phpgurukul | 1 Beauty Parlour Management System | 2026-07-05 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters. | |||||
| CVE-2024-53365 | 1 Phpgurukul | 1 Vehicle Parking Management System | 2026-07-05 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field. | |||||
| CVE-2024-52680 | 1 Eyoucms | 1 Eyoucms | 2026-07-05 | N/A | 6.1 MEDIUM |
| EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn. | |||||
| CVE-2024-51112 | 1 Pnetlab | 1 Pnetlab | 2026-07-05 | N/A | 6.1 MEDIUM |
| Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script | |||||
| CVE-2024-51111 | 1 Pnetlab | 1 Pnetlab | 2026-07-05 | N/A | 4.1 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of the victim's browser. | |||||
| CVE-2024-48417 | 1 Edimax | 2 Br-6476ac, Br-6476ac Firmware | 2026-07-05 | N/A | 5.2 MEDIUM |
| Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter. | |||||
| CVE-2024-46606 | 1 Piwigo | 1 Piwigo | 2026-07-05 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | |||||
| CVE-2024-46605 | 1 Piwigo | 1 Piwigo | 2026-07-05 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | |||||
| CVE-2024-45932 | 1 Webkul | 1 Krayin Crm | 2026-07-05 | N/A | 4.8 MEDIUM |
| Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. | |||||
