Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-66390 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke… Wicket 10.10.0+ Fix from $1,6002026-07-27 MEDIUM 6.1 CVE-2026-52760 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. … Activemq 5.19.8 / 6.2.7+ Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2026-34033 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: thro… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-29170 A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing F… HTTP Server 2.4.68+ Fix from $1,6002026-06-08 MEDIUM 6.1 CVE-2026-42253 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The Mess… Activemq 5.19.7 / 6.2.6+ Fix from $1,6002026-06-01 MEDIUM 6.1 CVE-2026-45249 A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache EChart… Echarts 6.1.0+ Fix from $1,6002026-05-25 MEDIUM 6.1 CVE-2026-31379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31906 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-42509 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke… Wicket 10.9.0+ Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2026-41043 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticate… Activemq 5.19.6 / 6.2.5+ Fix from $1,6002026-04-24 MEDIUM 5.4 CVE-2026-35565 Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI … Storm 2.8.6+ Fix from $1,6002026-04-13 MEDIUM 6.8 CVE-2026-23794 Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Sync… Syncope 3.0.16 / 4.0.4+ Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2025-61623 Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to… Ofbiz 24.09.03+ Fix from $1,6002025-11-12 MEDIUM 6.1 CVE-2024-44088 Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a… Geode 1.15.2+ Fix from $1,6002025-10-14 MEDIUM 6.1 CVE-2024-41177 Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recomme… Zeppelin 0.12.0+ Fix from $1,6002025-08-03 MEDIUM 6.1 CVE-2025-24854 A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute … Jspwiki 2.12.3+ Fix from $1,6002025-07-31 HIGH 7.5 CVE-2025-24853 A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the v… Jspwiki 2.12.3+ Fix from $1,9502025-07-31 MEDIUM 6.1 CVE-2025-30676EPSS 65% Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… Ofbiz 18.12.19+ Fix from $1,6002025-04-01 MEDIUM 5.4 CVE-2024-53679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with… Vcl 2.5.2+ Fix from $1,6002025-03-25 MEDIUM 5.4 CVE-2025-26796 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. … Oozie Mitigation only Fix from $1,6002025-03-22 MEDIUM 5.4 CVE-2025-27888 Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… Druid 31.0.2+ Fix from $1,6002025-03-20 MEDIUM 5.6 CVE-2025-27867 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issu… Felix Http Webconsole Plugin 1.2.2+ Fix from $1,6002025-03-12 MEDIUM 6.1 CVE-2025-25247 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Ap… Felix Webconsole 4.9.10 / 5.0.10+ Fix from $1,6002025-02-10 MEDIUM 6.1 CVE-2024-45031 When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored X… Syncope 3.0.9+ Fix from $1,6002024-10-24 MEDIUM 6.1 CVE-2024-41937 Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting atta… Airflow 2.10.0+ Fix from $1,6002024-08-21 MEDIUM 5.4 CVE-2024-25090 Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of … Roller 6.1.3+ Fix from $1,6002024-07-26 MEDIUM 5.4 CVE-2024-38503 When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The… Syncope 3.0.8+ Fix from $1,6002024-07-22 MEDIUM 5.4 CVE-2024-39863 Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider… Airflow 2.9.3+ Fix from $1,6002024-07-17 MEDIUM 5.4 CVE-2024-37389EPSS 24% Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable… Nifi 1.27.0+ Fix from $1,6002024-07-08 MEDIUM 6.1 CVE-2024-27136EPSS 59% XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive infor… Jspwiki 2.12.2+ Fix from $1,6002024-06-24