Vulnerability index

Browse CVEs

104 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Pen Drive MEDIUM 6.9
CVE-2026-13083

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An at…

Fix: 1.0.0-2+
Fix from $1,600 2026-06-26
Build Of Keycloak HIGH 7.3
CVE-2026-9086

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien…

Fix: 26.4.13 / 26.6.4+
Fix from $1,950 2026-06-25
Advanced Cluster Security MEDIUM 5.4
CVE-2025-5198

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. T…

Patch available
Fix from $1,600 2025-05-27
Codeready Studio MEDIUM 6.1
CVE-2023-1932

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, w…

Fix: 6.2+
Fix from $1,600 2024-11-07
Build Of Keycloak HIGH 7.3
CVE-2024-10234

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or…

Mitigation only
Fix from $1,950 2024-10-22
Ansible Automation Platform MEDIUM 6.1
CVE-2024-10033

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us…

Mitigation only
Fix from $1,600 2024-10-16
Single Sign On MEDIUM 5.4
CVE-2023-6134

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could al…

Fix: 7.6 / 22.0.7+
Fix from $1,600 2023-12-14
Enterprise Linux MEDIUM 5.4
CVE-2023-6710

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the…

Mitigation only
Fix from $1,600 2023-12-12
Ansible Automation Controller MEDIUM 5.4
CVE-2023-3971

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a cust…

Fix: 4.3.11+
Fix from $1,600 2023-10-04
Keycloak MEDIUM 6.1
CVE-2022-4137

A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m…

Mitigation only
Fix from $1,600 2023-09-25
Satellite MEDIUM 5.4
CVE-2023-0119

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As…

Mitigation only
Fix from $1,600 2023-09-12
Quay MEDIUM 5.4
CVE-2023-3384

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex …

Mitigation only
Fix from $1,600 2023-07-24
Keycloak MEDIUM 6.1
CVE-2022-4361

Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The v…

Fix: 7.6.4 / 21.1.2+
Fix from $1,600 2023-07-07
Keycloak MEDIUM 5.4
CVE-2022-1274

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak user…

Fix: 7.6.2 / 20.0.5+
Fix from $1,600 2023-03-29
Build Of Quarkus MEDIUM 6.1
CVE-2023-0044

If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Info…

Fix: 2.13.7+
Fix from $1,600 2023-02-23
Bodhi MEDIUM 6.1
CVE-2020-15855

Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.

Fix: 5.6.1+
Fix from $1,600 2022-10-07
Ansible Automation Platform MEDIUM 6.1
CVE-2022-3205

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje…

Mitigation only
Fix from $1,600 2022-09-13
Keycloak MEDIUM 5.4
CVE-2022-0225

A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t…

No fix yet
Fix from $1,600 2022-08-26
Build Of Quarkus MEDIUM 6.1
CVE-2021-3914

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cro…

Fix: 2.7.5+
Fix from $1,600 2022-08-25
Jboss Aerogear MEDIUM 5.4
CVE-2014-3650

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us…

Mitigation only
Fix from $1,600 2022-07-01
Keycloak MEDIUM 6.1
CVE-2021-20323EPSS 37%

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

Fix: 17.0.0+
Fix from $1,600 2022-03-25
Resteasy MEDIUM 6.1
CVE-2021-20293

A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL…

Fix: after 4.6.0
Fix from $1,600 2021-06-10
Noobaa Operator HIGH 7.1
CVE-2021-3529

A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as p…

Fix: 5.7.0+
Fix from $1,950 2021-06-02
Fuse MEDIUM 6.1
CVE-2020-10688

A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL …

Fix: 3.11.1 / 4.5.3+
Fix from $1,600 2021-05-27
Quay CRITICAL 9.0
CVE-2020-27832

A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…

Fix: 3.3.2+
Fix from $2,300 2021-05-27
Ceph Storage MEDIUM 6.1
CVE-2021-3509

A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to a…

Patch available
Fix from $1,600 2021-05-27
Keycloak HIGH 7.5
CVE-2021-20222

A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat …

Fix: 13.0.0+
Fix from $1,950 2021-03-23
Software Collections MEDIUM 6.1
CVE-2020-27783

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behavi…

Fix: 4.6.2+
Fix from $1,600 2020-12-03
Ceph Storage MEDIUM 6.1
CVE-2020-25626

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails…

Fix: 3.12.0+
Fix from $1,600 2020-09-30
Pagure MEDIUM 6.1
CVE-2019-11556

Pagure before 5.6 allows XSS via the templates/blame.html blame view.

Fix: 5.6+
Fix from $1,600 2020-09-25