Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Firefox MEDIUM 5.4
CVE-2026-9308

Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a…

Fix: 151.2+
Fix from $1,600 2026-06-01
Firefox MEDIUM 5.4
CVE-2026-9309

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View beha…

Fix: 151.2+
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-25599

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation o…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.3
CVE-2026-8474

A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is …

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 8.7
CVE-2026-9024

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2…

Mitigation only
Fix from $1,950 2026-06-01
Activemq MEDIUM 6.1
CVE-2026-42253

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The Mess…

Fix: 5.19.7 / 6.2.6+
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.1
CVE-2026-40544

SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backu…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.1
CVE-2026-40545

SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim,…

Mitigation only
Fix from $1,600 2026-06-01
Otrs HIGH 7.1
CVE-2026-48209

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform…

Fix: after 7.0.49
Fix from $1,950 2026-06-01
Pycharm MEDIUM 6.1
CVE-2026-49384

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

Fix: 2025.3.4+
Fix from $1,600 2026-05-29
Teamcity MEDIUM 6.1
CVE-2026-49375

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

Fix: 2025.11.5+
Fix from $1,600 2026-05-29
Youtrack MEDIUM 5.4
CVE-2026-49368

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Fix: 2026.1.13162+
Fix from $1,600 2026-05-29
Teamcity HIGH 8.2
CVE-2026-49371

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Fix: 2026.1.1+
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.9
CVE-2026-44651

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified HIGH 8.4
CVE-2026-6824

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input i…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.3
CVE-2026-45668

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malic…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 8.2
CVE-2026-45627

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo e…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.1
CVE-2026-36324

SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user …

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.4
CVE-2018-25384

Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted H…

No fix yet
Fix from $1,600 2026-05-29
Avideo MEDIUM 5.4
CVE-2026-47694

WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_des…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo MEDIUM 5.4
CVE-2026-45580

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-s…

Fix: after 29.0
Fix from $1,600 2026-05-29
Unclassified HIGH 8.7
CVE-2026-48527

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scriptin…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 5.1
CVE-2026-45551

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authen…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.4
CVE-2026-9811

A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associatin…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified HIGH 7.6
CVE-2026-9809

A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administ…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.4
CVE-2026-9243

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carouse…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified HIGH 7.2
CVE-2025-11262

The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and includin…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.4
CVE-2025-14042

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom fi…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 6.4
CVE-2026-6275

The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 6.4
CVE-2026-9714

The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in v…

Mitigation only
Fix from $1,600 2026-05-29