Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Experience Manager MEDIUM 5.4
CVE-2026-47945

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47946

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47947

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47948

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47949

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47950

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47951

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47935

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47936

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47939

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47941

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47942

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47943

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47640

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 5.4
CVE-2026-47631

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47634

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47636

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47637

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47638

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47639

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Live Share Canvas HIGH 8.0
CVE-2026-45644

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker…

Fix: 1.4.2+
Fix from $1,950 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45500

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45501

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45479

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45481

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45483

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45467

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45468

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45462

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45464

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09