Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-13253

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/ad…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-13334

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including,…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-13771

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all version…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-12170

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit…

Mitigation only
Fix from $1,600 2026-07-09
Dynamics 365 Customer Voice MEDIUM 6.1
CVE-2026-47646

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t…

Mitigation only
Fix from $1,600 2026-07-09
Chrome MEDIUM 6.1
CVE-2026-15127

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) v…

Fix: 150.0.7871.115+
Fix from $1,600 2026-07-08
Chrome MEDIUM 6.1
CVE-2026-15128

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) v…

Fix: 150.0.7871.115+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.9
CVE-2026-5922

The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.

Mitigation only
Fix from $1,600 2026-07-08
Ux MEDIUM 6.1
CVE-2026-55877

Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_saf…

Fix: 2.36.1 / 3.2.0+
Fix from $1,600 2026-07-08
GitLab MEDIUM 5.4
CVE-2026-6896

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under c…

Fix: 18.11.7 / 19.0.4+
Fix from $1,600 2026-07-08
Appium\/base Driver MEDIUM 6.1
CVE-2026-58191

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-dri…

Fix: 10.7.0+
Fix from $1,600 2026-07-08
Unclassified HIGH 8.7
CVE-2026-55596

Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadat…

Patch available
Fix from $1,950 2026-07-08
Jupyterlab Git CRITICAL 9.0
CVE-2026-54527

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames direct…

Fix: 0.54.0+
Fix from $2,300 2026-07-08
GitLab MEDIUM 5.4
CVE-2026-13320

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under…

Fix: 18.11.7 / 19.0.4+
Fix from $1,600 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-59926

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatena…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-59929

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only java…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Hono MEDIUM 6.1
CVE-2026-59895

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class name…

Fix: 4.12.27+
Fix from $1,600 2026-07-08
Mistune MEDIUM 6.1
CVE-2026-59923

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URI…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.0
CVE-2026-57439

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a k…

Patch available
Fix from $1,600 2026-07-08
Moveit Transfer MEDIUM 5.4
CVE-2026-11903

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This…

Fix: 2025.0.8 / 2025.1.4+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.1
CVE-2026-60092

AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin'…

Patch available
Fix from $1,600 2026-07-08
N8n MEDIUM 5.4
CVE-2026-56359

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaS…

Fix: 2.6.4 / 2.8.0+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.4
CVE-2026-56283

Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML c…

Mitigation only
Fix from $1,600 2026-07-08
Data Domain Operating System HIGH 7.1
CVE-2026-41122

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: 7.13.1.80 / 8.3.1.40+
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.1
CVE-2026-8310

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflecte…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.4
CVE-2026-8315

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored X…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.4
CVE-2026-6459

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.4
CVE-2026-6740

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'co…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 7.2
CVE-2026-6820

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.2
CVE-2026-6818

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in a…

Mitigation only
Fix from $1,950 2026-07-08