Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-66390
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket.
This issue affects Apache Wicke…
Wicket
10.10.0+
MEDIUM 6.1
CVE-2026-52760
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console.
…
Activemq
5.19.8 / 6.2.7+
MEDIUM 5.4
CVE-2026-34033
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: thro…
Answer
2.0.1+
MEDIUM 6.1
CVE-2026-29170
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing F…
HTTP Server
2.4.68+
MEDIUM 6.1
CVE-2026-42253
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The Mess…
Activemq
5.19.7 / 6.2.6+
MEDIUM 6.1
CVE-2026-45249
A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic.
This issue affects Apache EChart…
Echarts
6.1.0+
MEDIUM 6.1
CVE-2026-31379
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…
Ofbiz
24.09.06+
MEDIUM 6.1
CVE-2026-31906
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz:…
Ofbiz
24.09.06+
MEDIUM 6.1
CVE-2026-42509
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket.
This issue affects Apache Wicke…
Wicket
10.9.0+
MEDIUM 6.5
CVE-2026-41043
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticate…
Activemq
5.19.6 / 6.2.5+
MEDIUM 5.4
CVE-2026-35565
Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI
Versions Affected: before 2.8.6
Description: The Storm UI …
Storm
2.8.6+
MEDIUM 6.8
CVE-2026-23794
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Sync…
Syncope
3.0.16 / 4.0.4+
MEDIUM 6.5
CVE-2025-61623
Reflected cross-site scripting vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommended to upgrade to…
Ofbiz
24.09.03+
MEDIUM 6.1
CVE-2024-44088
Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a…
Geode
1.15.2+
MEDIUM 6.1
CVE-2024-41177
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin.
This issue affects Apache Zeppelin: before 0.12.0.
Users are recomme…
Zeppelin
0.12.0+
MEDIUM 6.1
CVE-2025-24854
A carefully crafted request using the Image plugin could trigger an XSS
vulnerability on Apache JSPWiki, which could allow the attacker to
execute …
Jspwiki
2.12.3+
HIGH 7.5
CVE-2025-24853
A carefully crafted request when creating a header link using the
wiki markup syntax, which could allow the attacker to execute javascript
in the v…
Jspwiki
2.12.3+
MEDIUM 6.1
CVE-2025-30676EPSS 65%
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before…
Ofbiz
18.12.19+
MEDIUM 5.4
CVE-2024-53679
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with…
Vcl
2.5.2+
MEDIUM 5.4
CVE-2025-26796
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie.
…
Oozie
Mitigation only
MEDIUM 5.4
CVE-2025-27888
Severity: medium (5.8) / important
Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
Druid
31.0.2+
MEDIUM 5.6
CVE-2025-27867
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin.
This issu…
Felix Http Webconsole Plugin
1.2.2+
MEDIUM 6.1
CVE-2025-25247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.
This issue affects Ap…
Felix Webconsole
4.9.10 / 5.0.10+
MEDIUM 6.1
CVE-2024-45031
When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored X…
Syncope
3.0.9+
MEDIUM 6.1
CVE-2024-41937
Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting atta…
Airflow
2.10.0+
MEDIUM 5.4
CVE-2024-25090
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …
Roller
6.1.3+
MEDIUM 5.4
CVE-2024-38503
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.
The…
Syncope
3.0.8+
MEDIUM 5.4
CVE-2024-39863
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider…
Airflow
2.9.3+
MEDIUM 5.4
CVE-2024-37389EPSS 24%
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable…
Nifi
1.27.0+
MEDIUM 6.1
CVE-2024-27136EPSS 59%
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive infor…
Jspwiki
2.12.2+