Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.2
CVE-2020-37222

Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submi…

No fix yet
Fix from $1,950 2026-05-13
Unclassified MEDIUM 5.5
CVE-2020-37174

WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject mal…

No fix yet
Fix from $1,600 2026-05-13
Unclassified HIGH 7.2
CVE-2026-6177

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insu…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified MEDIUM 6.4
CVE-2026-3004

The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.5
CVE-2025-14767

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_bes…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.4
CVE-2026-6828

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.4
CVE-2026-6962

The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'…

Mitigation only
Fix from $1,600 2026-05-13
Policy Reporter Ui MEDIUM 6.1
CVE-2026-44245

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented…

Fix: 2.5.2+
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.1
CVE-2026-42157

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a r…

Mitigation only
Fix from $1,600 2026-05-12
Ip Address MEDIUM 6.1
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do …

Fix: 10.1.1+
Fix from $1,600 2026-05-12
Commerce HIGH 8.7
CVE-2026-34686

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (X…

Mitigation only
Fix from $1,950 2026-05-12
Arubaos HIGH 8.8
CVE-2026-23819

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacke…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-43892

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal fo…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.2
CVE-2026-42045

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat process…

Mitigation only
Fix from $1,600 2026-05-12
Visual Studio Code MEDIUM 5.0
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …

Fix: 1.119.1+
Fix from $1,600 2026-05-12
Unclassified HIGH 8.1
CVE-2026-43938

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) ca…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.3
CVE-2026-43939

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content vi…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 5.4
CVE-2025-70842

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated a…

Patch available
Fix from $1,600 2026-05-12
Firefox MEDIUM 5.3
CVE-2026-8391

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb…

Fix: 150.0.3+
Fix from $1,600 2026-05-12
Unclassified HIGH 7.1
CVE-2026-25789

Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer …

Mitigation only
Fix from $1,950 2026-05-12
Teamcenter MEDIUM 6.1
CVE-2026-33862

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (…

Fix: 2312.0014 / 2406.0012+
Fix from $1,600 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-25786

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This c…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-25787

Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web inter…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-7661

The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.1
CVE-2026-7437

The AzonPost plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `editpos_hidden` parameter in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.1
CVE-2026-7464

The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, a…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-7659

The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, a…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.1
CVE-2026-6808

The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-6913

The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-5715

The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all ve…

No fix yet
Fix from $1,600 2026-05-12