Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Firewall Community MEDIUM 5.4
CVE-2026-34810

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated att…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34811

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated …

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34803

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated att…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34804

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attac…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34805

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated atta…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34806

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated atta…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34799

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34800

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticate…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34801

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authentic…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34802

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An a…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34798

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated a…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Phpmyfaq MEDIUM 6.1
CVE-2026-32629

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that…

Fix: 4.1.1+
Fix from $1,600 2026-04-02
Panel MEDIUM 6.1
CVE-2026-5332

A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. Th…

Mitigation only
Fix from $1,600 2026-04-02
Flowmon MEDIUM 6.1
CVE-2026-2737

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an a…

Fix: 12.5.8 / 13.0.6+
Fix from $1,600 2026-04-02
Unclassified MEDIUM 6.5
CVE-2026-34890

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-B…

Mitigation only
Fix from $1,600 2026-04-02
Secure Email Gateway MEDIUM 6.1
CVE-2026-29136

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.

Fix: 15.0.3+
Fix from $1,600 2026-04-02
Content Navigator MEDIUM 5.4
CVE-2026-1243

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr…

Mitigation only
Fix from $1,600 2026-04-02
Aspera Shares MEDIUM 5.4
CVE-2025-66484

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34571

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34565

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34566

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34567

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34568

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34569

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34560

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms HIGH 8.4
CVE-2026-34561

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $1,950 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34562

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34563

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34564

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34559

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01