Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-33276 Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to ex… Checkmk Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-20915 Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes… Checkmk Mitigation only Fix from $1,6002026-03-31 HIGH 7.2 CVE-2026-4267 The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['R… Mitigation only Fix from $1,9502026-03-31 MEDIUM 6.5 CVE-2026-34887 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stor… Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2025-41355 Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in… Anon Proxy Server Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2025-41356 Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in t… Anon Proxy Server Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2025-41357 Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in t… Anon Proxy Server Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-3106 Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' paramet… Teampass 3.1.5.24+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-3107 Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpo… Teampass 3.1.5.24+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2025-10551 A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE … 3dexperience Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2025-10553 A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE … 3dexperience Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-1877 The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to m… Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-4146 The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and in… Mitigation only Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-30879 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has … Basercms 5.2.3+ Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-32734 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been… Basercms 5.2.3+ Fix from $1,6002026-03-31 CRITICAL 9.0 CVE-2026-34557 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-03-30 CRITICAL 9.0 CVE-2026-34558 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-03-30 HIGH 7.2 CVE-2026-27599 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $1,9502026-03-30 CRITICAL 9.1 CVE-2026-32275 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP cal… Tautulli 2.17.0+ Fix from $2,3002026-03-30 MEDIUM 6.1 CVE-2026-27508 Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improp… Smoothwall Express after 3.0 Fix from $1,6002026-03-30 MEDIUM 5.4 CVE-2026-26352 Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to impr… Smoothwall Express after 3.0 Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30556 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the ind… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30557 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30558 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30559 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30560 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30561 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 CRITICAL 9.3 CVE-2026-30562 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add… Sales And Inventory System No fix yet Fix from $2,3002026-03-30 MEDIUM 6.1 CVE-2026-30082 Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow a… Mitigation only Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30563 A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update… Sales And Inventory System No fix yet Fix from $1,6002026-03-30