Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-30564 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30565 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.1 CVE-2026-30566 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie… Sales And Inventory System No fix yet Fix from $1,6002026-03-30 MEDIUM 6.4 CVE-2026-2602 The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and inclu… Mitigation only Fix from $1,6002026-03-29 MEDIUM 5.4 CVE-2026-2595 The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1… Mitigation only Fix from $1,6002026-03-28 HIGH 8.6 CVE-2026-33955 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison vi… Notesnook Desktop 3.3.11+ Fix from $1,9502026-03-27 CRITICAL 9.6 CVE-2026-33976 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can … Notesnook Desktop 3.3.11 / 3.3.17+ Fix from $2,3002026-03-27 HIGH 8.2 CVE-2026-33979 Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to preve… Express Xss Sanitizer 2.0.2+ Fix from $1,9502026-03-27 HIGH 8.2 CVE-2026-33941 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/… Handlebars 4.7.9+ Fix from $1,9502026-03-27 MEDIUM 6.1 CVE-2026-33883 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could … Statamic 5.73.16 / 6.7.2+ Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-33045 Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20… Home Assistant 2026.1.0+ Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-33044 Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20… Home Assistant 2026.1.0+ Fix from $1,6002026-03-27 HIGH 8.2 CVE-2026-34375 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes th… Avideo after 26.0 Fix from $1,9502026-03-27 MEDIUM 6.1 CVE-2026-30567 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "li… Inventory System No fix yet Fix from $1,6002026-03-27 MEDIUM 6.1 CVE-2026-30569 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie… Inventory System No fix yet Fix from $1,6002026-03-27 MEDIUM 6.1 CVE-2026-30570 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_sales.php file via the "limi… Inventory System No fix yet Fix from $1,6002026-03-27 MEDIUM 6.1 CVE-2026-30571 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "l… Inventory System No fix yet Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-30527 A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within … Online Food Ordering System No fix yet Fix from $1,6002026-03-27 MEDIUM 5.1 CVE-2026-5010 A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript cod… Mitigation only Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-5026 The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content. S… Langflow Mitigation only Fix from $1,6002026-03-27 MEDIUM 6.1 CVE-2026-33758 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authenticatio… Openbao 2.5.2+ Fix from $1,6002026-03-27 MEDIUM 6.1 CVE-2025-61190 A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The … Dspace No fix yet Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-32859 ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to… Patch available Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-25100 Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges… Bludit 3.18.2+ Fix from $1,6002026-03-27 HIGH 7.0 CVE-2026-3457 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows a… Mitigation only Fix from $1,9502026-03-27 MEDIUM 5.4 CVE-2026-33559 WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin … Mitigation only Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-33673 PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS)… Prestashop 8.2.5 / 9.1.0+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-33653 Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2… Uploady 3.1.2+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-33664 Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — des… Kestra after 1.3.3 Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-3529 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics GA4 allows Cross-Site S… Google Analytics Ga4 1.1.14+ Fix from $1,6002026-03-26