Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Fabric.js MEDIUM 6.1
CVE-2026-44311

Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to impro…

Fix: 7.4.0+
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.4
CVE-2026-48167

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEn…

Mitigation only
Fix from $1,600 2026-06-22
Jupyter Server MEDIUM 5.4
CVE-2026-44727

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored noteboo…

Fix: 2.20.0+
Fix from $1,600 2026-06-22
Astro MEDIUM 6.1
CVE-2026-54298

Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passe…

Fix: 6.4.6+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50555

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.25 / 20.3.24+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50556

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.25 / 20.3.24+
Fix from $1,600 2026-06-22
Datacap MEDIUM 6.1
CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allow…

Mitigation only
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-54265

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, …

Fix: 20.3.25 / 21.2.17+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-54267

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, …

Fix: 20.3.25 / 21.2.17+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50557

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.22 / 20.3.22+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-52725

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.23 / 20.3.22+
Fix from $1,600 2026-06-22
Angular Language Service HIGH 8.8
CVE-2026-50178

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS …

Fix: 21.2.4+
Fix from $1,950 2026-06-22
Angular Language Service HIGH 8.8
CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Lan…

Fix: 21.2.4+
Fix from $1,950 2026-06-22
Tririga Application Platform MEDIUM 5.4
CVE-2026-11372

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed …

Mitigation only
Fix from $1,600 2026-06-22
Grafana MEDIUM 5.4
CVE-2026-9029

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The …

Mitigation only
Fix from $1,600 2026-06-22
Engineering Workflow Management MEDIUM 5.4
CVE-2025-33128

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. T…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 5.4
CVE-2026-12580

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent Java…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified HIGH 8.1
CVE-2023-45796

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows …

Mitigation only
Fix from $1,950 2026-06-22
Unclassified HIGH 7.8
CVE-2023-45795

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicio…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified HIGH 7.1
CVE-2026-4259

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, l…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified HIGH 7.1
CVE-2026-6858

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stor…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified CRITICAL 9.6
CVE-2026-56395

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar…

Mitigation only
Fix from $2,300 2026-06-21
Unclassified CRITICAL 9.6
CVE-2026-56397

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar…

Mitigation only
Fix from $2,300 2026-06-21
Unclassified MEDIUM 6.1
CVE-2026-56347

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding…

Mitigation only
Fix from $1,600 2026-06-20
Nuxt MEDIUM 6.1
CVE-2026-56317

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content…

Fix: 3.21.7 / 4.4.7+
Fix from $1,600 2026-06-20
Edge Chromium MEDIUM 5.4
CVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s…

Mitigation only
Fix from $1,600 2026-06-19
Gridtime 3000 Firmware MEDIUM 5.4
CVE-2026-12621

Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue aff…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Gridtime 3000 Firmware MEDIUM 5.4
CVE-2026-12619

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Sit…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Unclassified MEDIUM 6.3
CVE-2026-21768

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input t…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 5.6
CVE-2026-8296

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

Mitigation only
Fix from $1,600 2026-06-19