Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-1276 IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed… Qradar Security Information And Event Manager Mitigation only Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-32703 OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories modul… Openproject 16.6.9 / 17.0.6+ Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-32722 Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML … Memray 1.19.2+ Fix from $1,6002026-03-18 HIGH 7.6 CVE-2026-32728 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attack… Parse Server 8.6.41 / 9.6.0+ Fix from $1,9502026-03-18 CRITICAL 9.8 CVE-2026-29859 An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. Aapanel Mitigation only Fix from $2,3002026-03-18 MEDIUM 5.4 CVE-2026-30048 A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized b… Mitigation only Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-30695 A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, … Mitigation only Fix from $1,6002026-03-18 HIGH 7.2 CVE-2026-3090 The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable … Mitigation only Fix from $1,9502026-03-18 MEDIUM 6.4 CVE-2026-2512 The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2… Mitigation only Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-3278 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Si… Zenworks Service Desk Mitigation only Fix from $1,6002026-03-18 MEDIUM 5.3 CVE-2025-12518 beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary… Mitigation only Fix from $1,6002026-03-18 HIGH 7.1 CVE-2026-22322 A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create… Mitigation only Fix from $1,9502026-03-18 MEDIUM 5.9 CVE-2025-15363 The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-S… Mitigation only Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-3512 The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and in… Mitigation only Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-31938 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows att… Jspdf 4.2.1+ Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-1780 The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including,… Mitigation only Fix from $1,6002026-03-18 MEDIUM 6.4 CVE-2026-4268 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in al… Mitigation only Fix from $1,6002026-03-18 MEDIUM 6.1 CVE-2026-28499 LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a c… Leafkit 1.14.2+ Fix from $1,6002026-03-18 MEDIUM 5.4 CVE-2026-32840 Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows… Gs 5008pl Firmware after 1.00.54 Fix from $1,6002026-03-17 MEDIUM 6.1 CVE-2025-62320 HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Becau… Unica 12.1.11 / 25.1.1.0.1+ Fix from $1,6002026-03-17 MEDIUM 6.1 CVE-2026-30882 Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in t… Chamilo Lms 1.11.36+ Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2026-29510 Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to injec… Eth Imc408m Firmware after 1.0.15 Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2026-29513 Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to injec… Eth Imc408m Firmware after 1.0.15 Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2026-29520 Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function th… Eth Imc408m Firmware after 1.0.15 Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2025-65734 An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows at… Openeclass 3.13+ Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2025-57543 Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be render… Netbox No fix yet Fix from $1,6002026-03-16 HIGH 7.1 CVE-2026-25369 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflect… Mitigation only Fix from $1,9502026-03-16 MEDIUM 6.1 CVE-2025-2274 Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web … Web Security after 8.5.6 Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2026-3024 Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/mod… Wakyma Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2026-32774 Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts.… Vulnogram Patch available Fix from $1,6002026-03-16