Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-13253 The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/ad… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.1 CVE-2026-13334 The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including,… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-13771 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all version… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-12170 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.1 CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t… Dynamics 365 Customer Voice Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.1 CVE-2026-15127 Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) v… Chrome 150.0.7871.115+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-15128 Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) v… Chrome 150.0.7871.115+ Fix from $1,6002026-07-08 MEDIUM 5.9 CVE-2026-5922 The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage. Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-55877 Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_saf… Ux 2.36.1 / 3.2.0+ Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-6896 GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under c… GitLab 18.11.7 / 19.0.4+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-58191 Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-dri… Appium\/base Driver 10.7.0+ Fix from $1,6002026-07-08 HIGH 8.7 CVE-2026-55596 Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadat… Patch available Fix from $1,9502026-07-08 CRITICAL 9.0 CVE-2026-54527 JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames direct… Jupyterlab Git 0.54.0+ Fix from $2,3002026-07-08 MEDIUM 5.4 CVE-2026-13320 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under… GitLab 18.11.7 / 19.0.4+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-59926 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatena… Mistune 3.3.0+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-59929 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only java… Mistune 3.3.0+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-59895 Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class name… Hono 4.12.27+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-59923 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URI… Mistune 3.3.0+ Fix from $1,6002026-07-08 MEDIUM 5.0 CVE-2026-57439 CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a k… Patch available Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-11903 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This… Moveit Transfer 2025.0.8 / 2025.1.4+ Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-60092 AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin'… Patch available Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-56359 n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaS… N8n 2.6.4 / 2.8.0+ Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-56283 Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML c… Mitigation only Fix from $1,6002026-07-08 HIGH 7.1 CVE-2026-41122 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug… Data Domain Operating System 7.13.1.80 / 8.3.1.40+ Fix from $1,9502026-07-08 MEDIUM 6.1 CVE-2026-8310 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflecte… Mitigation only Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-8315 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored X… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2026-6459 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2026-6740 The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'co… Mitigation only Fix from $1,6002026-07-08 HIGH 7.2 CVE-2026-6820 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions… Mitigation only Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-6818 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in a… Mitigation only Fix from $1,9502026-07-08