Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Flowsint MEDIUM 5.4
CVE-2026-42159

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flo…

Fix: 1.2.3+
Fix from $1,600 2026-05-14
Unclassified MEDIUM 5.3
CVE-2026-44371

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascr…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified CRITICAL 9.6
CVE-2026-44482

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.0
CVE-2026-42457

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified MEDIUM 6.1
CVE-2026-41932

Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies r…

Patch available
Fix from $1,600 2026-05-14
Verba Collaboration Compliance And Quality Management Platform MEDIUM 6.1
CVE-2026-21730

Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker at…

Fix: 10.0.6+
Fix from $1,600 2026-05-14
Cfengine MEDIUM 6.1
CVE-2026-24710

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.

Fix: 3.21.8 / 3.24.3+
Fix from $1,600 2026-05-14
Unclassified MEDIUM 5.1
CVE-2026-1630

WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL tha…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 5.1
CVE-2026-5790

Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employee…

Mitigation only
Fix from $1,600 2026-05-14
Podinfo MEDIUM 6.1
CVE-2026-43644

podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes requ…

Fix: after 6.11.12
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.4
CVE-2026-6174

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.4
CVE-2026-6504

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versi…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.4
CVE-2026-6252

The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified HIGH 7.2
CVE-2026-3718

The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up t…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified MEDIUM 6.4
CVE-2026-3694

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the bt_bb_button shortcode in all…

Mitigation only
Fix from $1,600 2026-05-14
GitLab MEDIUM 5.4
CVE-2026-7377

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in c…

Fix: 18.9.7 / 18.10.6+
Fix from $1,600 2026-05-14
GitLab MEDIUM 5.4
CVE-2026-7481

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could…

Fix: 18.9.7 / 18.10.6+
Fix from $1,600 2026-05-14
GitLab MEDIUM 5.4
CVE-2026-6073

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could…

Fix: 18.9.7 / 18.10.6+
Fix from $1,600 2026-05-14
GitLab MEDIUM 5.4
CVE-2026-6335

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an a…

Fix: 18.11.3+
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.1
CVE-2026-6417

The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failed_orders' parameter in all versio…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.4
CVE-2026-5243

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to store…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.4
CVE-2026-5361

The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. Th…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 5.4
CVE-2026-45228

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config…

Patch available
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.1
CVE-2026-44376

CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature…

Patch available
Fix from $1,600 2026-05-13
Empirbus Wireless Display Unit Firmware MEDIUM 5.0
CVE-2025-27852

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on …

Mitigation only
Fix from $1,600 2026-05-13
Unclassified HIGH 8.6
CVE-2026-42548

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query parameter directly into an applicati…

Mitigation only
Fix from $1,950 2026-05-13
Next.js MEDIUM 6.1
CVE-2026-44580

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteract…

Fix: 15.5.16 / 16.2.5+
Fix from $1,600 2026-05-13
Astro MEDIUM 6.1
CVE-2026-45028

Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props …

Fix: 6.1.10+
Fix from $1,600 2026-05-13
Jupyterlab CRITICAL 9.6
CVE-2026-42557

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, Jupyt…

Fix: 4.5.7 / 7.5.6+
Fix from $2,300 2026-05-13
Unclassified MEDIUM 6.4
CVE-2020-37225

Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary Ja…

No fix yet
Fix from $1,600 2026-05-13