Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.1
CVE-2026-47345

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo…

Patch available
Fix from $1,600 2026-06-08
HTTP Server MEDIUM 6.1
CVE-2026-29170

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing F…

Fix: 2.4.68+
Fix from $1,600 2026-06-08
Checkmk MEDIUM 5.4
CVE-2026-7186

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboar…

Mitigation only
Fix from $1,600 2026-06-08
Checkmk MEDIUM 5.4
CVE-2026-8833

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions a…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified MEDIUM 5.4
CVE-2026-11569

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.4
CVE-2026-3011

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes…

Mitigation only
Fix from $1,600 2026-06-08
Aria Operations MEDIUM 5.4
CVE-2026-41722

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies…

Fix: 8.18.7 / 9.0.2.0+
Fix from $1,600 2026-06-08
Aria Operations HIGH 8.0
CVE-2026-41723

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies…

Fix: 8.18.7 / 9.0.2.0+
Fix from $1,950 2026-06-08
Aria Operations MEDIUM 5.4
CVE-2026-41724

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies…

Fix: 8.18.7+
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.4
CVE-2021-47982

WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scrip…

No fix yet
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.4
CVE-2021-47983

WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious …

No fix yet
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.4
CVE-2021-47984

WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious…

No fix yet
Fix from $1,600 2026-06-08
Unclassified HIGH 7.2
CVE-2023-54351

WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scri…

No fix yet
Fix from $1,950 2026-06-08
Unclassified MEDIUM 6.4
CVE-2026-7796

The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.1
CVE-2026-9280

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in …

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.4
CVE-2026-7795

The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versi…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified HIGH 7.2
CVE-2026-8901

The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site S…

Mitigation only
Fix from $1,950 2026-06-06
Unclassified MEDIUM 6.4
CVE-2026-9281

The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cros…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified HIGH 7.2
CVE-2026-8438

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includ…

Mitigation only
Fix from $1,950 2026-06-06
Unclassified MEDIUM 6.4
CVE-2026-8900

The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.4
CVE-2026-8893

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] sho…

Mitigation only
Fix from $1,600 2026-06-06
Open Xdmod MEDIUM 5.4
CVE-2026-45778

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious Java…

Fix: 11.0.3+
Fix from $1,600 2026-06-05
Unclassified CRITICAL 9.3
CVE-2026-46496

HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified HIGH 8.7
CVE-2026-46511

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic …

Mitigation only
Fix from $1,950 2026-06-05
Unclassified CRITICAL 9.3
CVE-2026-46396

HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified MEDIUM 6.1
CVE-2026-38579

Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbi…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified MEDIUM 6.1
CVE-2026-50230

Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers t…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified HIGH 7.2
CVE-2026-50231

Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject mal…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 7.2
CVE-2026-50232

Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file m…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified MEDIUM 6.1
CVE-2026-50235

Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user i…

Mitigation only
Fix from $1,600 2026-06-05