Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.9
CVE-2026-13083
A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An at…
Pen Drive
1.0.0-2+
HIGH 7.3
CVE-2026-9086
A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien…
Build Of Keycloak
26.4.13 / 26.6.4+
MEDIUM 5.4
CVE-2025-5198
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. T…
Advanced Cluster Security
Patch available
MEDIUM 6.1
CVE-2023-1932
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, w…
Codeready Studio
6.2+
HIGH 7.3
CVE-2024-10234
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or…
Build Of Keycloak
Mitigation only
MEDIUM 6.1
CVE-2024-10033
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us…
Ansible Automation Platform
Mitigation only
MEDIUM 5.4
CVE-2023-6134
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could al…
Single Sign On
7.6 / 22.0.7+
MEDIUM 5.4
CVE-2023-6710
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the…
Enterprise Linux
Mitigation only
MEDIUM 5.4
CVE-2023-3971
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a cust…
Ansible Automation Controller
4.3.11+
MEDIUM 6.1
CVE-2022-4137
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m…
Keycloak
Mitigation only
MEDIUM 5.4
CVE-2023-0119
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As…
Satellite
Mitigation only
MEDIUM 5.4
CVE-2023-3384
A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex …
Quay
Mitigation only
MEDIUM 6.1
CVE-2022-4361
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The v…
Keycloak
7.6.4 / 21.1.2+
MEDIUM 5.4
CVE-2022-1274
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak user…
Keycloak
7.6.2 / 20.0.5+
MEDIUM 6.1
CVE-2023-0044
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Info…
Build Of Quarkus
2.13.7+
MEDIUM 6.1
CVE-2020-15855
Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.
Bodhi
5.6.1+
MEDIUM 6.1
CVE-2022-3205
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje…
Ansible Automation Platform
Mitigation only
MEDIUM 5.4
CVE-2022-0225
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t…
Keycloak
No fix yet
MEDIUM 6.1
CVE-2021-3914
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cro…
Build Of Quarkus
2.7.5+
MEDIUM 5.4
CVE-2014-3650
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us…
Jboss Aerogear
Mitigation only
MEDIUM 6.1
CVE-2021-20323EPSS 37%
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
Keycloak
17.0.0+
MEDIUM 6.1
CVE-2021-20293
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL…
Resteasy
after 4.6.0
HIGH 7.1
CVE-2021-3529
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as p…
Noobaa Operator
5.7.0+
MEDIUM 6.1
CVE-2020-10688
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL …
Fuse
3.11.1 / 4.5.3+
CRITICAL 9.0
CVE-2020-27832
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…
Quay
3.3.2+
MEDIUM 6.1
CVE-2021-3509
A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to a…
Ceph Storage
Patch available
HIGH 7.5
CVE-2021-20222
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat …
Keycloak
13.0.0+
MEDIUM 6.1
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behavi…
Software Collections
4.6.2+
MEDIUM 6.1
CVE-2020-25626
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails…
Ceph Storage
3.12.0+
MEDIUM 6.1
CVE-2019-11556
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
Pagure
5.6+