Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 8.8 CVE-2026-60636 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content Mitigation only Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60637 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60638 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60639 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60633 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-52475 Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file No fix yet Fix from $1,6002026-07-21 HIGH 8.7 CVE-2026-47685 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenti… Fogproject 1.5.10.1832+ Fix from $1,9502026-07-21 HIGH 8.7 CVE-2026-47687 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectFor… Fogproject 1.5.10.1832+ Fix from $1,9502026-07-21 MEDIUM 5.2 CVE-2026-47689 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow(… Fogproject 1.5.10.1832+ Fix from $1,6002026-07-21 HIGH 8.1 CVE-2026-50758 Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter Mitigation only Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-55081 DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflect… Patch available Fix from $1,9502026-07-21 MEDIUM 6.2 CVE-2026-28315 SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclos… Serv U 2026.3+ Fix from $1,6002026-07-21 CRITICAL 9.3 CVE-2026-65048 Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatab… No fix yet Fix from $2,3002026-07-21 MEDIUM 5.4 CVE-2026-64628 Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads con… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.4 CVE-2026-15145 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fanc… Patch available Fix from $1,6002026-07-21 HIGH 8.8 CVE-2026-11767 The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputti… Mitigation only Fix from $1,9502026-07-21 MEDIUM 6.4 CVE-2026-15156 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Read… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2023-37508 HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain brows… Devops Plan 3.0.5+ Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-51025 Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageCo… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.4 CVE-2026-12900 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/i… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-44229 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a… Request Tracker 5.0.10 / 6.0.3+ Fix from $1,6002026-07-20 MEDIUM 6.1 CVE-2026-44230 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not in… Request Tracker 5.0.10 / 6.0.3+ Fix from $1,6002026-07-20 HIGH 8.6 CVE-2026-60028 Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable … No fix yet Fix from $1,9502026-07-20 MEDIUM 5.1 CVE-2026-60029 Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable … No fix yet Fix from $1,6002026-07-20 CRITICAL 9.4 CVE-2026-60034 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS … No fix yet Fix from $2,3002026-07-20 MEDIUM 6.1 CVE-2026-44227 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scri… Request Tracker 6.0.3+ Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-44228 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Script… Request Tracker 6.0.3+ Fix from $1,6002026-07-20 CRITICAL 9.3 CVE-2026-39878 Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti… Mitigation only Fix from $2,3002026-07-20 MEDIUM 6.1 CVE-2026-26483 Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The applicat… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-6793 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT … No fix yet Fix from $1,6002026-07-20