Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-9308 Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a… Firefox 151.2+ Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-9309 Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View beha… Firefox 151.2+ Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-25599 Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation o… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.3 CVE-2026-8474 A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is … Mitigation only Fix from $1,6002026-06-01 HIGH 8.7 CVE-2026-9024 A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.1 CVE-2026-42253 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The Mess… Activemq 5.19.7 / 6.2.6+ Fix from $1,6002026-06-01 MEDIUM 5.1 CVE-2026-40544 SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backu… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.1 CVE-2026-40545 SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim,… Mitigation only Fix from $1,6002026-06-01 HIGH 7.1 CVE-2026-48209 An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform… Otrs after 7.0.49 Fix from $1,9502026-06-01 MEDIUM 6.1 CVE-2026-49384 In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible Pycharm 2025.3.4+ Fix from $1,6002026-05-29 MEDIUM 6.1 CVE-2026-49375 In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page Teamcity 2025.11.5+ Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2026-49368 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible Youtrack 2026.1.13162+ Fix from $1,6002026-05-29 HIGH 8.2 CVE-2026-49371 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible Teamcity 2026.1.1+ Fix from $1,9502026-05-29 MEDIUM 6.9 CVE-2026-44651 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $1,6002026-05-29 HIGH 8.4 CVE-2026-6824 A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input i… Mitigation only Fix from $1,9502026-05-29 CRITICAL 9.3 CVE-2026-45668 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malic… Mitigation only Fix from $2,3002026-05-29 HIGH 8.2 CVE-2026-45627 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo e… Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.1 CVE-2026-36324 SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user … Mitigation only Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2018-25384 Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted H… No fix yet Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2026-47694 WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_des… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2026-45580 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-s… Avideo after 29.0 Fix from $1,6002026-05-29 HIGH 8.7 CVE-2026-48527 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scriptin… Mitigation only Fix from $1,9502026-05-29 MEDIUM 5.1 CVE-2026-45551 Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authen… Mitigation only Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2026-9811 A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associatin… Mitigation only Fix from $1,6002026-05-29 HIGH 7.6 CVE-2026-9809 A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administ… Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.4 CVE-2026-9243 The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carouse… Mitigation only Fix from $1,6002026-05-29 HIGH 7.2 CVE-2025-11262 The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and includin… Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.4 CVE-2025-14042 The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom fi… Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.4 CVE-2026-6275 The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.4 CVE-2026-9714 The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in v… Mitigation only Fix from $1,6002026-05-29