Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Dompurify MEDIUM 6.1
CVE-2026-49458

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accept…

Fix: 3.4.6+
Fix from $1,600 2026-07-14
Dompurify MEDIUM 6.1
CVE-2026-49459

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could …

Fix: 3.4.6+
Fix from $1,600 2026-07-14
Coldfusion HIGH 8.5
CVE-2026-48320EPSS 5%

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scri…

Mitigation only
Fix from $1,950 2026-07-14
Symfony MEDIUM 6.1
CVE-2026-48761

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAtt…

Fix: 6.4.41 / 7.4.13+
Fix from $1,600 2026-07-14
Commerce MEDIUM 5.4
CVE-2026-48371

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…

Fix: 1.21.0+
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48355

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48262

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48263

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48253

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48254

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48255

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48257

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48260

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Experience Manager MEDIUM 5.4
CVE-2026-48261

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…

Fix: after 2020.5.0
Fix from $1,600 2026-07-14
Commerce HIGH 8.7
CVE-2026-47994

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…

Fix: 1.21.0+
Fix from $1,950 2026-07-14
Commerce HIGH 8.1
CVE-2026-47995

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject maliciou…

Fix: 1.21.0+
Fix from $1,950 2026-07-14
Dompurify HIGH 8.2
CVE-2026-47423

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing br…

Patch available
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.6
CVE-2026-47428

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCa…

Patch available
Fix from $2,300 2026-07-14
Symfony MEDIUM 6.1
CVE-2026-45753

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, …

Fix: 6.4.40 / 7.4.12+
Fix from $1,600 2026-07-14
Symfony MEDIUM 5.4
CVE-2026-45072

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the d…

Fix: 6.4.40 / 7.4.12+
Fix from $1,600 2026-07-14
Visual Studio Code MEDIUM 6.1
CVE-2026-57101

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …

Fix: 1.128.1+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55135

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55126

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server HIGH 8.7
CVE-2026-55034

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55016

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55019

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55020

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server HIGH 8.7
CVE-2026-55021

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
Power Bi Report Server MEDIUM 5.4
CVE-2026-58647

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing ov…

Fix: 15.0.1121.120+
Fix from $1,600 2026-07-14