Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-6565 The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scr… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.1 CVE-2026-44903 Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy we… Prometheus 3.5.3 / 3.11.3+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-44896 Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() functio… Mistune after 3.2.0 Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-44897 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concaten… Mistune 3.2.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-44898 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (… Mistune 3.2.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-44899 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options… Mistune 3.2.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-44708 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($… Mistune 3.2.1+ Fix from $1,6002026-05-26 MEDIUM 5.4 CVE-2026-44831 Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, r… Snipe It 8.4.1+ Fix from $1,6002026-05-26 MEDIUM 5.2 CVE-2025-68709 SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivit… Mitigation only Fix from $1,6002026-05-26 HIGH 8.7 CVE-2026-44667 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via… Mitigation only Fix from $1,9502026-05-26 HIGH 8.7 CVE-2026-44669 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via… Mitigation only Fix from $1,9502026-05-26 MEDIUM 6.1 CVE-2026-48903 Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-48905 Lack of input filtering leads to an XSS vector in the HTML filter code. Joomla\! 5.4.6 / 6.1.0+ Fix from $1,6002026-05-26 HIGH 8.7 CVE-2026-44729 Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded fi… Twenty after 1.18.0 Fix from $1,9502026-05-26 MEDIUM 6.1 CVE-2026-30895 Lack of output escaping leads to a XSS vector in the readmore links for com_content. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-25900 Lack of output escaping leads to a XSS vector in the feed modules. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-25901 Lack of output escaping leads to a XSS vector in the multilingual associations component. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-30894 Lack of output escaping leads to a XSS vector in the content history component. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2025-36148 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerabl… Financial Transaction Manager For Multiplatform 3.2.4.16+ Fix from $1,6002026-05-26 HIGH 7.6 CVE-2025-36126 IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) … Cognos Analytics 12.1.2+ Fix from $1,9502026-05-26 MEDIUM 6.5 CVE-2026-27427 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This … Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.5 CVE-2026-45435 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS.… Mitigation only Fix from $1,6002026-05-25 MEDIUM 6.5 CVE-2025-62745 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. T… Mitigation only Fix from $1,6002026-05-25 HIGH 7.2 CVE-2026-48848 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injecti… Patch available Fix from $1,9502026-05-25 MEDIUM 6.1 CVE-2026-45249 A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache EChart… Echarts 6.1.0+ Fix from $1,6002026-05-25 MEDIUM 6.1 CVE-2018-25349 userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP hea… No fix yet Fix from $1,6002026-05-23 HIGH 8.7 CVE-2026-41147 NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insu… Patch available Fix from $1,9502026-05-22 HIGH 7.2 CVE-2026-40596 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML b… Patch available Fix from $1,9502026-05-22 HIGH 7.6 CVE-2026-40597 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerabilit… Patch available Fix from $1,9502026-05-22 MEDIUM 6.9 CVE-2026-40598 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved fro… Patch available Fix from $1,6002026-05-22