Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-22520 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework a… No fix yet Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-22523 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin … Mitigation only Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-22524 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows R… Mitigation only Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-22491 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro… Mitigation only Fix from $1,9502026-03-25 HIGH 7.1 CVE-2025-69096 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zorka allows Reflected XSS.This i… Mitigation only Fix from $1,9502026-03-25 MEDIUM 5.4 CVE-2026-3212 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS)… Tagify 1.2.49+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-3215 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora allows Cross-Site Scripting (X… Islandora 2.17.5+ Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2026-3217 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross… Saml Sso Service Provider 3.1.3+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-2348 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (… Quick Edit 1.0.5+ Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2026-2349 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons allows Cross-Site Scripting (XS… Ui Icons 1.0.1+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-24750 Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper… Kiteworks 9.2.1+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-20108 A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cro… Catalyst Sd Wan Manager 20.12.5.3 / 20.15.4.2+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-4816 A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScr… Support Board 3.7.8+ Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2025-40842 Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthori… Indoor Connect 8855 Firmware 2025.q3+ Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2026-2072 Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue af… Infrastructure Analytics Advisor 11.0.5-00+ Fix from $1,6002026-03-25 MEDIUM 6.4 CVE-2026-4766 The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up… Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2026-33347 league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerab… Commonmark 2.8.2+ Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2026-33331 oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.9, a stored cross-site scr… Orpc 1.13.9+ Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2026-33400 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in t… Wallos 4.7.0+ Fix from $1,6002026-03-24 CRITICAL 9.6 CVE-2026-33334 Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w… Vikunja 2.2.2+ Fix from $2,3002026-03-24 MEDIUM 5.4 CVE-2026-29840 JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. T… Jizhicms after 2.5.6 Fix from $1,6002026-03-24 MEDIUM 6.1 CVE-2026-30661 iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allow… Icms No fix yet Fix from $1,6002026-03-24 MEDIUM 6.1 CVE-2026-4754 CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. Android Imagemagick7 7.1.2-11+ Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2026-4626 A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The m… Online Lawyer Management System No fix yet Fix from $1,6002026-03-24 MEDIUM 6.1 CVE-2026-33170 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-24 MEDIUM 6.1 CVE-2026-33167 Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions p… Rails 8.1.2.1+ Fix from $1,6002026-03-23 HIGH 8.7 CVE-2026-32277 Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue… Connect Cms 1.41.1 / 2.41.1+ Fix from $1,9502026-03-23 MEDIUM 5.4 CVE-2025-60948 Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that… Csweb Patch available Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-32851 MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex… Mailenable 10.55+ Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-32852 MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex… Mailenable 10.55+ Fix from $1,6002026-03-23