Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.5
CVE-2026-32424

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows S…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.9
CVE-2026-32419

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Briano List category posts list-catego…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32411

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed Calendly embed-calendly-scheduling…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion …

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32359

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.9
CVE-2026-32360

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews wi…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32361

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-cal…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.9
CVE-2026-32351

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32352

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor a…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32356

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows DOM-B…

Mitigation only
Fix from $1,600 2026-03-13
Oneuptime HIGH 7.6
CVE-2026-32308

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with se…

Fix: 10.0.23+
Fix from $1,950 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-31918

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in immonex immonex Kickstart immonex-kickstart all…

Mitigation only
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.5
CVE-2026-22209

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 6.1
CVE-2026-22210

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.4
CVE-2026-22183

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated use…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 5.4
CVE-2026-0835

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 5.4
CVE-2025-14504

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2025-13702

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,600 2026-03-13
Vertica MEDIUM 6.1
CVE-2025-12453

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vu…

Fix: 25.4.0-0+
Fix from $1,600 2026-03-13
Vertica MEDIUM 6.1
CVE-2025-12454

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vu…

Fix: 25.2.0+
Fix from $1,600 2026-03-13
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-40693

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vul…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-13
Dataease MEDIUM 5.4
CVE-2026-32139

Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads…

Fix: 2.10.20+
Fix from $1,600 2026-03-12
Unhead MEDIUM 6.1
CVE-2026-31860

Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event h…

Fix: 2.1.11+
Fix from $1,600 2026-03-12
Unhead MEDIUM 6.1
CVE-2026-31873

Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses String.includes(), which is case-s…

Fix: 2.1.11+
Fix from $1,600 2026-03-12
Postal HIGH 8.1
CVE-2026-25529

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included i…

Fix: 3.3.5+
Fix from $1,950 2026-03-12
Unclassified HIGH 8.6
CVE-2026-2513

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by …

Mitigation only
Fix from $1,950 2026-03-12
Unclassified HIGH 8.6
CVE-2026-2514

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may …

Mitigation only
Fix from $1,950 2026-03-12
Unclassified MEDIUM 6.1
CVE-2026-2987

The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 202602…

Mitigation only
Fix from $1,600 2026-03-12
Grafanacubism Panel MEDIUM 5.4
CVE-2026-32117

The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supp…

Fix: after 0.1.2
Fix from $1,600 2026-03-11
Openemr MEDIUM 5.4
CVE-2026-32124

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJ…

Fix: 8.0.0.1+
Fix from $1,600 2026-03-11