Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-6565

The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Mitigation only
Fix from $1,600 2026-05-27
Prometheus MEDIUM 6.1
CVE-2026-44903

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy we…

Fix: 3.5.3 / 3.11.3+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44896

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() functio…

Fix: after 3.2.0
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44897

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concaten…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44898

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44899

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Mistune MEDIUM 6.1
CVE-2026-44708

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($…

Fix: 3.2.1+
Fix from $1,600 2026-05-26
Snipe It MEDIUM 5.4
CVE-2026-44831

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, r…

Fix: 8.4.1+
Fix from $1,600 2026-05-26
Unclassified MEDIUM 5.2
CVE-2025-68709

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivit…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified HIGH 8.7
CVE-2026-44667

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 8.7
CVE-2026-44669

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via…

Mitigation only
Fix from $1,950 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-48903

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-48905

Lack of input filtering leads to an XSS vector in the HTML filter code.

Fix: 5.4.6 / 6.1.0+
Fix from $1,600 2026-05-26
Twenty HIGH 8.7
CVE-2026-44729

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded fi…

Fix: after 1.18.0
Fix from $1,950 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-30895

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-25900

Lack of output escaping leads to a XSS vector in the feed modules.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-25901

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-30894

Lack of output escaping leads to a XSS vector in the content history component.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Financial Transaction Manager For Multiplatform MEDIUM 6.1
CVE-2025-36148

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerabl…

Fix: 3.2.4.16+
Fix from $1,600 2026-05-26
Cognos Analytics HIGH 7.6
CVE-2025-36126

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) …

Fix: 12.1.2+
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.5
CVE-2026-27427

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This …

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 6.5
CVE-2026-45435

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS.…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.5
CVE-2025-62745

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. T…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified HIGH 7.2
CVE-2026-48848

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injecti…

Patch available
Fix from $1,950 2026-05-25
Echarts MEDIUM 6.1
CVE-2026-45249

A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache EChart…

Fix: 6.1.0+
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.1
CVE-2018-25349

userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP hea…

No fix yet
Fix from $1,600 2026-05-23
Unclassified HIGH 8.7
CVE-2026-41147

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insu…

Patch available
Fix from $1,950 2026-05-22
Unclassified HIGH 7.2
CVE-2026-40596

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML b…

Patch available
Fix from $1,950 2026-05-22
Unclassified HIGH 7.6
CVE-2026-40597

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerabilit…

Patch available
Fix from $1,950 2026-05-22
Unclassified MEDIUM 6.9
CVE-2026-40598

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved fro…

Patch available
Fix from $1,600 2026-05-22