Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 8.7 CVE-2026-35218 Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, querie… Budibase 3.32.5+ Fix from $1,9502026-04-03 MEDIUM 5.4 CVE-2026-5468 A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument … Casdoor Mitigation only Fix from $1,6002026-04-03 MEDIUM 5.4 CVE-2026-4107 Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. Manageengine Exchange Reporter Plus 5.8+ Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-35539 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mod… Webmail 1.5.14 / 1.6.14+ Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-35508 Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters, Shynet 0.14.0+ Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-30251 A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attack… Zenshare Suite Mitigation only Fix from $1,6002026-04-02 MEDIUM 6.1 CVE-2026-30252 Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows atta… Zencrm Mitigation only Fix from $1,6002026-04-02 MEDIUM 6.1 CVE-2026-35466 XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services Cveclient 1.0.24+ Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34848 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow to… Hoppscotch 2026.3.0+ Fix from $1,6002026-04-02 CRITICAL 9.3 CVE-2026-34932 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is… Hoppscotch 2026.3.0+ Fix from $2,3002026-04-02 HIGH 7.8 CVE-2026-5429 Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat acto… Mitigation only Fix from $1,9502026-04-02 HIGH 8.2 CVE-2026-34725 DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-c… Patch available Fix from $1,9502026-04-02 MEDIUM 6.1 CVE-2026-34606 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, … Learning 2.48.0+ Fix from $1,6002026-04-02 MEDIUM 6.1 CVE-2026-34598 YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious att… Yeswiki 4.6.0+ Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34821 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An auth… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34822 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authe… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34823 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated … Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34974 phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed … Phpmyfaq 4.1.1+ Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34816 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An auth… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34817 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authen… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34818 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authen… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34819 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authentic… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34820 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacke… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34812 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenti… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34813 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated a… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34814 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34815 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticat… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34807 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated … Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34808 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticate… Firewall Community after 3.3.25 Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34809 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated at… Firewall Community after 3.3.25 Fix from $1,6002026-04-02