Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2026-1276

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed…

Mitigation only
Fix from $1,600 2026-03-19
Openproject MEDIUM 5.4
CVE-2026-32703

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories modul…

Fix: 16.6.9 / 17.0.6+
Fix from $1,600 2026-03-18
Memray MEDIUM 6.1
CVE-2026-32722

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML …

Fix: 1.19.2+
Fix from $1,600 2026-03-18
Parse Server HIGH 7.6
CVE-2026-32728

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attack…

Fix: 8.6.41 / 9.6.0+
Fix from $1,950 2026-03-18
Aapanel CRITICAL 9.8
CVE-2026-29859

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.

Mitigation only
Fix from $2,300 2026-03-18
Unclassified MEDIUM 5.4
CVE-2026-30048

A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized b…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified MEDIUM 6.1
CVE-2026-30695

A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, …

Mitigation only
Fix from $1,600 2026-03-18
Unclassified HIGH 7.2
CVE-2026-3090

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable …

Mitigation only
Fix from $1,950 2026-03-18
Unclassified MEDIUM 6.4
CVE-2026-2512

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2…

Mitigation only
Fix from $1,600 2026-03-18
Zenworks Service Desk MEDIUM 6.1
CVE-2026-3278

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Si…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified MEDIUM 5.3
CVE-2025-12518

beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified HIGH 7.1
CVE-2026-22322

A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create…

Mitigation only
Fix from $1,950 2026-03-18
Unclassified MEDIUM 5.9
CVE-2025-15363

The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-S…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified MEDIUM 6.1
CVE-2026-3512

The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and in…

Mitigation only
Fix from $1,600 2026-03-18
Jspdf MEDIUM 6.1
CVE-2026-31938

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows att…

Fix: 4.2.1+
Fix from $1,600 2026-03-18
Unclassified MEDIUM 6.1
CVE-2026-1780

The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including,…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified MEDIUM 6.4
CVE-2026-4268

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in al…

Mitigation only
Fix from $1,600 2026-03-18
Leafkit MEDIUM 6.1
CVE-2026-28499

LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a c…

Fix: 1.14.2+
Fix from $1,600 2026-03-18
Gs 5008pl Firmware MEDIUM 5.4
CVE-2026-32840

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows…

Fix: after 1.00.54
Fix from $1,600 2026-03-17
Unica MEDIUM 6.1
CVE-2025-62320

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Becau…

Fix: 12.1.11 / 25.1.1.0.1+
Fix from $1,600 2026-03-17
Chamilo Lms MEDIUM 6.1
CVE-2026-30882

Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in t…

Fix: 1.11.36+
Fix from $1,600 2026-03-16
Eth Imc408m Firmware MEDIUM 5.4
CVE-2026-29510

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to injec…

Fix: after 1.0.15
Fix from $1,600 2026-03-16
Eth Imc408m Firmware MEDIUM 5.4
CVE-2026-29513

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to injec…

Fix: after 1.0.15
Fix from $1,600 2026-03-16
Eth Imc408m Firmware MEDIUM 6.1
CVE-2026-29520

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function th…

Fix: after 1.0.15
Fix from $1,600 2026-03-16
Openeclass MEDIUM 5.4
CVE-2025-65734

An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows at…

Fix: 3.13+
Fix from $1,600 2026-03-16
Netbox MEDIUM 6.1
CVE-2025-57543

Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be render…

No fix yet
Fix from $1,600 2026-03-16
Unclassified HIGH 7.1
CVE-2026-25369

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflect…

Mitigation only
Fix from $1,950 2026-03-16
Web Security MEDIUM 6.1
CVE-2025-2274

Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web …

Fix: after 8.5.6
Fix from $1,600 2026-03-16
Wakyma MEDIUM 5.4
CVE-2026-3024

Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/mod…

Mitigation only
Fix from $1,600 2026-03-16
Vulnogram MEDIUM 5.4
CVE-2026-32774

Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts.…

Patch available
Fix from $1,600 2026-03-16