Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-73084 Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied c… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-71386 is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attack… No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-70355 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 CRITICAL 9.3 CVE-2026-70306 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20434+ Fix from $5,7502026-08-11 HIGH 7.6 CVE-2026-65767 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to … Teams 1.0.76.202611302+ Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-64922 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-64916 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-64902 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-64897 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-64900 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-62914 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to pe… Exchange Server 15.02.2562.046+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-62829 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 CRITICAL 9.6 CVE-2026-57104 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele… Azure Storage Explorer No fix yet Fix from $5,7502026-08-11 MEDIUM 5.4 CVE-2026-57105 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-21269 is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into v… Coldfusion No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-18247 A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentiall… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.1 CVE-2026-72925 SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.1 CVE-2026-19434 Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the app… No fix yet Fix from $4,0002026-08-11 HIGH 7.2 CVE-2026-72747 AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-72559 A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes … No fix yet Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-72553 A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.1 CVE-2026-73161 Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.1 CVE-2026-73158 Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.1 CVE-2026-73159 Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() … No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-73156 Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice name… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.4 CVE-2026-16974 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.3 CVE-2026-66779 Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.1 CVE-2026-66771 SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user … No fix yet Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-72743 SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders T… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.1 CVE-2026-69116 FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicio… No fix yet Fix from $4,0002026-08-10