Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.1 CVE-2026-47345 Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo… Patch available Fix from $1,6002026-06-08 MEDIUM 6.1 CVE-2026-29170 A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing F… HTTP Server 2.4.68+ Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-7186 Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboar… Checkmk Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-8833 Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions a… Checkmk Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-11569 A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access… Mitigation only Fix from $1,6002026-06-08 MEDIUM 6.4 CVE-2026-3011 The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes… Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-41722 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies… Aria Operations 8.18.7 / 9.0.2.0+ Fix from $1,6002026-06-08 HIGH 8.0 CVE-2026-41723 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies… Aria Operations 8.18.7 / 9.0.2.0+ Fix from $1,9502026-06-08 MEDIUM 5.4 CVE-2026-41724 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies… Aria Operations 8.18.7+ Fix from $1,6002026-06-08 MEDIUM 6.4 CVE-2021-47982 WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scrip… No fix yet Fix from $1,6002026-06-08 MEDIUM 6.4 CVE-2021-47983 WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious … No fix yet Fix from $1,6002026-06-08 MEDIUM 6.4 CVE-2021-47984 WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious… No fix yet Fix from $1,6002026-06-08 HIGH 7.2 CVE-2023-54351 WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scri… No fix yet Fix from $1,9502026-06-08 MEDIUM 6.4 CVE-2026-7796 The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.1 CVE-2026-9280 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in … Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.4 CVE-2026-7795 The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versi… Mitigation only Fix from $1,6002026-06-06 HIGH 7.2 CVE-2026-8901 The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site S… Mitigation only Fix from $1,9502026-06-06 MEDIUM 6.4 CVE-2026-9281 The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cros… Mitigation only Fix from $1,6002026-06-06 HIGH 7.2 CVE-2026-8438 The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includ… Mitigation only Fix from $1,9502026-06-06 MEDIUM 6.4 CVE-2026-8900 The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and includ… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.4 CVE-2026-8893 The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] sho… Mitigation only Fix from $1,6002026-06-06 MEDIUM 5.4 CVE-2026-45778 OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious Java… Open Xdmod 11.0.3+ Fix from $1,6002026-06-05 CRITICAL 9.3 CVE-2026-46496 HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26… Mitigation only Fix from $2,3002026-06-05 HIGH 8.7 CVE-2026-46511 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic … Mitigation only Fix from $1,9502026-06-05 CRITICAL 9.3 CVE-2026-46396 HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26… Mitigation only Fix from $2,3002026-06-05 MEDIUM 6.1 CVE-2026-38579 Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbi… Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.1 CVE-2026-50230 Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers t… Mitigation only Fix from $1,6002026-06-05 HIGH 7.2 CVE-2026-50231 Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject mal… Mitigation only Fix from $1,9502026-06-05 HIGH 7.2 CVE-2026-50232 Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file m… Mitigation only Fix from $1,9502026-06-05 MEDIUM 6.1 CVE-2026-50235 Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user i… Mitigation only Fix from $1,6002026-06-05