Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-44311 Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to impro… Fabric.js 7.4.0+ Fix from $1,6002026-06-22 MEDIUM 6.4 CVE-2026-48167 Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEn… Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2026-44727 Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored noteboo… Jupyter Server 2.20.0+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-54298 Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passe… Astro 6.4.6+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-50555 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.25 / 20.3.24+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-50556 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.25 / 20.3.24+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-8059 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allow… Datacap Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-54265 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, … Angular 20.3.25 / 21.2.17+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-54267 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, … Angular 20.3.25 / 21.2.17+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-50557 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.22 / 20.3.22+ Fix from $1,6002026-06-22 MEDIUM 6.1 CVE-2026-52725 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.23 / 20.3.22+ Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-50178 The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS … Angular Language Service 21.2.4+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-49241 The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Lan… Angular Language Service 21.2.4+ Fix from $1,9502026-06-22 MEDIUM 5.4 CVE-2026-11372 IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed … Tririga Application Platform Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2026-9029 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The … Grafana Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2025-33128 IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. T… Engineering Workflow Management Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.4 CVE-2026-12580 EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent Java… Mitigation only Fix from $1,6002026-06-22 HIGH 8.1 CVE-2023-45796 A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows … Mitigation only Fix from $1,9502026-06-22 HIGH 7.8 CVE-2023-45795 A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicio… Mitigation only Fix from $1,9502026-06-22 HIGH 7.1 CVE-2026-4259 The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, l… Mitigation only Fix from $1,9502026-06-22 HIGH 7.1 CVE-2026-6858 The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stor… Mitigation only Fix from $1,9502026-06-22 CRITICAL 9.6 CVE-2026-56395 SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar… Mitigation only Fix from $2,3002026-06-21 CRITICAL 9.6 CVE-2026-56397 SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar… Mitigation only Fix from $2,3002026-06-21 MEDIUM 6.1 CVE-2026-56347 AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding… Mitigation only Fix from $1,6002026-06-20 MEDIUM 6.1 CVE-2026-56317 Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content… Nuxt 3.21.7 / 4.4.7+ Fix from $1,6002026-06-20 MEDIUM 5.4 CVE-2026-32208 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s… Edge Chromium Mitigation only Fix from $1,6002026-06-19 MEDIUM 5.4 CVE-2026-12621 Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue aff… Gridtime 3000 Firmware 1.2r0.0+ Fix from $1,6002026-06-19 MEDIUM 5.4 CVE-2026-12619 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Sit… Gridtime 3000 Firmware 1.2r0.0+ Fix from $1,6002026-06-19 MEDIUM 6.3 CVE-2026-21768 The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input t… Mitigation only Fix from $1,6002026-06-19 MEDIUM 5.6 CVE-2026-8296 In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts. Mitigation only Fix from $1,6002026-06-19