Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-7678 Cross-site Scripting vulnerability in Oretnom23 CAR Driving School Management System 1.0
A vulnerability was found in SourceCodester Car Driving School Management System 1.0.
network
low complexity
oretnom23 CWE-79
6.1
2024-08-12 CVE-2024-7683 Cross-site Scripting vulnerability in Mayurik Advocate Office Management System 1.0
A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0.
network
low complexity
mayurik CWE-79
5.4
2024-08-12 CVE-2024-7684 Cross-site Scripting vulnerability in Mayurik Advocate Office Management System 1.0
A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0.
network
low complexity
mayurik CWE-79
5.4
2024-08-12 CVE-2024-7685 Cross-site Scripting vulnerability in Mayurik Advocate Office Management System 1.0
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0.
network
low complexity
mayurik CWE-79
5.4
2024-08-12 CVE-2024-7686 Cross-site Scripting vulnerability in Mayurik Advocate Office Management System 1.0
A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0.
network
low complexity
mayurik CWE-79
5.4
2024-08-08 CVE-2024-42366 Cross-site Scripting vulnerability in Vrcx-Team Vrcx
VRCX is an assistant/companion application for VRChat.
network
low complexity
vrcx-team CWE-79
critical
9.0
2024-08-08 CVE-2024-7394 Cross-site Scripting vulnerability in Concretecms Concrete CMS
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName().
network
low complexity
concretecms CWE-79
4.8
2024-08-08 CVE-2024-4207 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2.
network
low complexity
gitlab CWE-79
5.4
2024-08-08 CVE-2024-6892 Cross-site Scripting vulnerability in Journyx 11.5.4
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.
network
low complexity
journyx CWE-79
6.1
2024-08-07 CVE-2024-6706 Cross-site Scripting vulnerability in Openwebui Open Webui 0.1.105
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
network
low complexity
openwebui CWE-79
6.1