Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-49458 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accept… Dompurify 3.4.6+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-49459 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could … Dompurify 3.4.6+ Fix from $1,6002026-07-14 HIGH 8.5 CVE-2026-48320EPSS 5% ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scri… Coldfusion Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.1 CVE-2026-48761 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAtt… Symfony 6.4.41 / 7.4.13+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48371 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious… Commerce 1.21.0+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48355 Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48262 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48263 Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48253 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48254 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48255 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48257 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48260 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-48261 Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th… Experience Manager after 2020.5.0 Fix from $1,6002026-07-14 HIGH 8.7 CVE-2026-47994 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious… Commerce 1.21.0+ Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-47995 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject maliciou… Commerce 1.21.0+ Fix from $1,9502026-07-14 HIGH 8.2 CVE-2026-47423 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing br… Dompurify Patch available Fix from $1,9502026-07-14 CRITICAL 9.6 CVE-2026-47428 Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCa… Patch available Fix from $2,3002026-07-14 MEDIUM 6.1 CVE-2026-45753 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, … Symfony 6.4.40 / 7.4.12+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-45072 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the d… Symfony 6.4.40 / 7.4.12+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-57101 Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass … Visual Studio Code 1.128.1+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-55135 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-55126 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 HIGH 8.7 CVE-2026-55034 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,9502026-07-14 MEDIUM 5.4 CVE-2026-55030 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-55016 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-55019 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-55020 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 HIGH 8.7 CVE-2026-55021 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,9502026-07-14 MEDIUM 5.4 CVE-2026-58647 Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing ov… Power Bi Report Server 15.0.1121.120+ Fix from $1,6002026-07-14