Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Anythingllm CRITICAL 9.6
CVE-2026-32626

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An…

Fix: after 1.11.1
Fix from $2,300 2026-03-16
Angular Cli CRITICAL 9.0
CVE-2026-32635

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-n…

Fix: 19.2.0 / 21.2.4+
Fix from $2,300 2026-03-16
Raytha MEDIUM 5.4
CVE-2025-69241

Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbi…

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 6.1
CVE-2025-69242

Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated …

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 6.1
CVE-2025-69245

Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by…

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 5.4
CVE-2025-69236

Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated attacker with permissions to e…

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Raytha MEDIUM 5.4
CVE-2025-69237

Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to …

Fix: 1.4.6+
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.1
CVE-2017-20219

Serviio PRO 1.8 DLNA Media Streaming Server contains a DOM-based cross-site scripting vulnerability that allows attackers to execute arbitrary HTML a…

No fix yet
Fix from $1,600 2026-03-16
Unclassified HIGH 7.2
CVE-2016-20032

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script…

No fix yet
Fix from $1,950 2026-03-16
Streaming Engine MEDIUM 6.1
CVE-2016-20036

Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed throu…

No fix yet
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.1
CVE-2016-20027

ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script c…

No fix yet
Fix from $1,600 2026-03-16
Realtyscript MEDIUM 6.1
CVE-2015-20116

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename p…

No fix yet
Fix from $1,600 2026-03-16
Realtyscript MEDIUM 6.1
CVE-2015-20118

Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations int…

No fix yet
Fix from $1,600 2026-03-16
Realtyscript MEDIUM 5.4
CVE-2015-20119

Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious H…

No fix yet
Fix from $1,600 2026-03-16
Unclassified HIGH 7.5
CVE-2013-20006

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly s…

No fix yet
Fix from $1,950 2026-03-16
Realtyscript MEDIUM 6.1
CVE-2015-20114

Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code …

No fix yet
Fix from $1,600 2026-03-16
Realtyscript MEDIUM 6.1
CVE-2015-20115

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST p…

No fix yet
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.3
CVE-2013-20005

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in us…

No fix yet
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.4
CVE-2026-3986

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-03-13
Statamic MEDIUM 5.4
CVE-2026-32612

Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows a…

Fix: 6.6.2+
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32460

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 ult…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.9
CVE-2026-32462

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32454

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-B…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32455

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonom…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32450

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommer…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32448

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32449

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Event Post themify-event-post…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32430

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Addons for Elemento…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32431

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edi…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32429

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-…

Mitigation only
Fix from $1,600 2026-03-13