Vulnerability index

Browse CVEs

104 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.9 CVE-2026-13083 A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An at… Pen Drive 1.0.0-2+ Fix from $1,6002026-06-26 HIGH 7.3 CVE-2026-9086 A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien… Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,9502026-06-25 MEDIUM 5.4 CVE-2025-5198 A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. T… Advanced Cluster Security Patch available Fix from $1,6002025-05-27 MEDIUM 6.1 CVE-2023-1932 A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, w… Codeready Studio 6.2+ Fix from $1,6002024-11-07 HIGH 7.3 CVE-2024-10234 A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or… Build Of Keycloak Mitigation only Fix from $1,9502024-10-22 MEDIUM 6.1 CVE-2024-10033 A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us… Ansible Automation Platform Mitigation only Fix from $1,6002024-10-16 MEDIUM 5.4 CVE-2023-6134 A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could al… Single Sign On 7.6 / 22.0.7+ Fix from $1,6002023-12-14 MEDIUM 5.4 CVE-2023-6710 A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the… Enterprise Linux Mitigation only Fix from $1,6002023-12-12 MEDIUM 5.4 CVE-2023-3971 An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a cust… Ansible Automation Controller 4.3.11+ Fix from $1,6002023-10-04 MEDIUM 6.1 CVE-2022-4137 A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m… Keycloak Mitigation only Fix from $1,6002023-09-25 MEDIUM 5.4 CVE-2023-0119 A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As… Satellite Mitigation only Fix from $1,6002023-09-12 MEDIUM 5.4 CVE-2023-3384 A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex … Quay Mitigation only Fix from $1,6002023-07-24 MEDIUM 6.1 CVE-2022-4361 Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The v… Keycloak 7.6.4 / 21.1.2+ Fix from $1,6002023-07-07 MEDIUM 5.4 CVE-2022-1274 A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak user… Keycloak 7.6.2 / 20.0.5+ Fix from $1,6002023-03-29 MEDIUM 6.1 CVE-2023-0044 If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Info… Build Of Quarkus 2.13.7+ Fix from $1,6002023-02-23 MEDIUM 6.1 CVE-2020-15855 Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1. Bodhi 5.6.1+ Fix from $1,6002022-10-07 MEDIUM 6.1 CVE-2022-3205 Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-13 MEDIUM 5.4 CVE-2022-0225 A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t… Keycloak No fix yet Fix from $1,6002022-08-26 MEDIUM 6.1 CVE-2021-3914 It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cro… Build Of Quarkus 2.7.5+ Fix from $1,6002022-08-25 MEDIUM 5.4 CVE-2014-3650 Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us… Jboss Aerogear Mitigation only Fix from $1,6002022-07-01 MEDIUM 6.1 CVE-2021-20323EPSS 37% A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. Keycloak 17.0.0+ Fix from $1,6002022-03-25 MEDIUM 6.1 CVE-2021-20293 A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL… Resteasy after 4.6.0 Fix from $1,6002021-06-10 HIGH 7.1 CVE-2021-3529 A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as p… Noobaa Operator 5.7.0+ Fix from $1,9502021-06-02 MEDIUM 6.1 CVE-2020-10688 A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL … Fuse 3.11.1 / 4.5.3+ Fix from $1,6002021-05-27 CRITICAL 9.0 CVE-2020-27832 A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi… Quay 3.3.2+ Fix from $2,3002021-05-27 MEDIUM 6.1 CVE-2021-3509 A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to a… Ceph Storage Patch available Fix from $1,6002021-05-27 HIGH 7.5 CVE-2021-20222 A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat … Keycloak 13.0.0+ Fix from $1,9502021-03-23 MEDIUM 6.1 CVE-2020-27783 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behavi… Software Collections 4.6.2+ Fix from $1,6002020-12-03 MEDIUM 6.1 CVE-2020-25626 A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails… Ceph Storage 3.12.0+ Fix from $1,6002020-09-30 MEDIUM 6.1 CVE-2019-11556 Pagure before 5.6 allows XSS via the templates/blame.html blame view. Pagure 5.6+ Fix from $1,6002020-09-25