Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.1
CVE-2026-73084

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied c…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-71386

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attack…

No fix yet
Fix from $4,900 2026-08-11
Sharepoint Server HIGH 8.7
CVE-2026-70355

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Sharepoint Server CRITICAL 9.3
CVE-2026-70306

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20434+
Fix from $5,750 2026-08-11
Teams HIGH 7.6
CVE-2026-65767

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to …

Fix: 1.0.76.202611302+
Fix from $4,900 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-64922

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-64916

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-64902

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-64897

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-64900

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Exchange Server MEDIUM 5.4
CVE-2026-62914

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to pe…

Fix: 15.02.2562.046+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-62829

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Azure Storage Explorer CRITICAL 9.6
CVE-2026-57104

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele…

No fix yet
Fix from $5,750 2026-08-11
Sharepoint Server MEDIUM 5.4
CVE-2026-57105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Coldfusion MEDIUM 5.4
CVE-2026-21269

is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into v…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-18247

A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentiall…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-72925

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-19434

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the app…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.2
CVE-2026-72747

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-72559

A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-72553

A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73161

Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73158

Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73159

Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73156

Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice name…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-16974

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66779

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-66771

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-72743

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders T…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.1
CVE-2026-69116

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicio…

No fix yet
Fix from $4,000 2026-08-10