Export limit exceeded: 50173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50173 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100238 | 2026-09-30 | 6.1 Medium | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-92994 | 2026-09-30 | 8.8 High | ||
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | ||||
| CVE-2026-76718 | 1 Hewlett Packard Enterprise | 1 Hpe Oneview | 2026-09-30 | 8.2 High |
| A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. | ||||
| CVE-2026-76719 | 1 Hewlett Packard Enterprise | 1 Hpe Oneview | 2026-09-30 | 8.2 High |
| A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. | ||||
| CVE-2026-100294 | 1 Anjvision | 1 Yssd-rtmp-h5 | 2026-09-30 | 7.5 High |
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation. | ||||
| CVE-2026-96587 | 1 Viidure | 1 Dashcam Android Application | 2026-09-30 | 10 Critical |
| The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries. | ||||
| CVE-2026-84409 | 1 Lantronix | 1 G520 Series | 2026-09-30 | 7.5 High |
| The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device. | ||||
| CVE-2026-71189 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 3.5 Low |
| An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. | ||||
| CVE-2026-102771 | 2 Naichen, Thinkcmf | 2 Thinkcmf, Thinkcmf | 2026-09-30 | 4.7 Medium |
| A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. The manipulation leads to improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-103050 | 1 Wikimedia | 1 Mediawiki - Massmessage Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-103051 | 1 Wikimedia | 1 Mediawiki - Centralnotice Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-92712 | 2 Rockiger, Wordpress-extensions | 2 Reactpress, Reactpress | 2026-09-30 | 6.4 Medium |
| The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents(). | ||||
| CVE-2026-102386 | 2 Jacob N. Breetvelt, Wordpress-extensions | 2 Wp Photo Album Plus, Wp Photo Album Plus | 2026-09-30 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | ||||
| CVE-2026-102395 | 2 Supsystic, Wordpress-extensions | 2 Easy Google Maps, Easy Google Maps | 2026-09-30 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | ||||
| CVE-2026-102396 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-09-30 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-102398 | 2 Supsystic, Wordpress-extensions | 2 Popup By Supsystic, Popup By Supsystic | 2026-09-30 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions. | ||||
| CVE-2026-102830 | 1 Jupyter | 2 Jupyter Core, Jupyterlab | 2026-09-30 | 6.8 Medium |
| JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new Function, so loading the catalogue and translating a plural string executes the appended code in the authenticated JupyterLab origin. Where Jupyter Server kernels, terminals, and APIs are exposed, the code can use authenticated server APIs to read or modify files and run code. Impact is much more limited in JupyterLite because it typically lacks most exposed Jupyter Server surfaces. The default English locale is unaffected because it does not load a translation catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and JupyterLite Core 0.8.4. | ||||
| CVE-2026-12425 | 1 Powerschool | 1 Employee Access Center | 2026-09-30 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user. | ||||
| CVE-2026-103046 | 1 Wikimedia | 1 Mediawiki-wikilambda Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1. | ||||
| CVE-2026-102329 | 1 Google | 1 Chrome | 2026-09-30 | 6.1 Medium |
| Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High) | ||||