Export limit exceeded: 49131 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49131 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-2514 | 2 Progress, Progress Software | 2 Flowmon Anomaly Detection System, Flowmon Ads | 2026-09-03 | 6.1 Medium |
| In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context. | ||||
| CVE-2026-2513 | 2 Progress, Progress Software | 2 Flowmon Anomaly Detection System, Flowmon Ads | 2026-09-03 | 6.1 Medium |
| A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | ||||
| CVE-2026-84232 | 1 Redhat | 5 Ansible Automation Platform, Rhui, Satellite and 2 more | 2026-09-03 | 5.4 Medium |
| A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application. | ||||
| CVE-2024-7952 | 2 Rockwell Automation, Rockwellautomation | 2 Dataedgeplatform Datamosaix Private Cloud, Dataedgeplatform Datamosaix Private Cloud | 2026-09-03 | N/A |
| A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data. | ||||
| CVE-2025-15692 | 2 Icegram, Wordpress | 2 Icegram Express, Wordpress | 2026-09-03 | 3.5 Low |
| The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2026-84665 | 1 Jenkins Project | 1 Jenkins Sonarqube Scanner Plugin | 2026-09-03 | 8 High |
| Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | ||||
| CVE-2026-84673 | 1 Jenkins Project | 1 Jenkins Customizable Header Plugin | 2026-09-03 | 8.8 High |
| Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability. | ||||
| CVE-2026-85021 | 1 Langgenius | 1 Dify | 2026-09-03 | 4.3 Medium |
| A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-84437 | 1 Opencart | 1 Opencart | 2026-09-03 | 3.5 Low |
| A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation of the argument address_1 results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-19719 | 2 Inisev, Wordpress | 2 Social Media Share Buttons & Social Sharing Icons, Wordpress | 2026-09-03 | 6.8 Medium |
| The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | ||||
| CVE-2026-19723 | 2 Inisev, Wordpress | 2 Social Media Share Buttons & Social Sharing Icons, Wordpress | 2026-09-03 | 7.1 High |
| The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | ||||
| CVE-2026-82884 | 2 Aioseo, Wordpress | 2 All In One Seo, Wordpress | 2026-09-03 | 6.8 Medium |
| The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post. | ||||
| CVE-2026-82451 | 1 Formwork Project | 1 Formwork | 2026-09-03 | 6.1 Medium |
| Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel. | ||||
| CVE-2026-3457 | 2 Thales, Thalesgroup | 2 Sentinel Ldk Runtime, Sentinel Ldk Runtime | 2026-09-03 | 6.8 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22. | ||||
| CVE-2026-84677 | 1 Jenkins Project | 1 Jenkins Update-center2 | 2026-09-03 | 5.4 Medium |
| Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | ||||
| CVE-2026-75134 | 2 Seowriting, Wordpress | 2 Seowriting, Wordpress | 2026-09-03 | 6.4 Medium |
| SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise. | ||||
| CVE-2026-56127 | 1 Netgate | 2 Pfsense Ce, Pfsense Plus | 2026-09-03 | 5.4 Medium |
| pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML sanitization, then rendered without encoding in the firewall log table in /status_logs_filter.php. The payload executes in the browser of any user with the Status: Logs: Firewall privilege who views the affected log entries. | ||||
| CVE-2026-2573 | 2 Ataurr, Wordpress | 2 Gutenkit – Page Builder Blocks, Patterns, And Templates For Gutenberg Block Editor, Wordpress | 2026-09-03 | 6.4 Medium |
| The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCss’ parameter in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-73731 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-03 | 6.1 Medium |
| A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | ||||
| CVE-2026-73336 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 6.4 Medium |
| Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||||