Export limit exceeded: 50140 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50140 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79799 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 8.8 High |
| A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | ||||
| CVE-2026-14911 | 1 Asus | 1 Router | 2026-10-07 | N/A |
| Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | ||||
| CVE-2026-104073 | 1 Netbox-community | 1 Netbox | 2026-10-07 | 7.6 High |
| NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover. | ||||
| CVE-2026-79816 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 5.4 Medium |
| A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a victim's browser context within the affected client interface. | ||||
| CVE-2026-95166 | 2026-10-06 | 5.4 Medium | ||
| In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload. | ||||
| CVE-2026-103667 | 1 Gitea | 1 Gitea | 2026-10-06 | N/A |
| Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a `text/html` media type. When a victim who is authenticated to the instance opens the blob URL in a browser, the script runs on the Gitea origin and can perform actions as the victim, such as creating API tokens. | ||||
| CVE-2026-105089 | 1 Wwbn | 1 Avideo | 2026-10-06 | 8.7 High |
| WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers. | ||||
| CVE-2026-39758 | 2 Midtrans, Wordpress-extensions | 2 Midtrans-woocommerce, Midtrans-woocommerce | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | ||||
| CVE-2026-39766 | 2 Reputeinfosystems, Wordpress-extensions | 2 Arforms, Arforms | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | ||||
| CVE-2026-39768 | 2 Cleantalk, Wordpress-extensions | 2 Security & Malware Scan, Security & Malware Scan By Cleantalk | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions. | ||||
| CVE-2026-39778 | 2 Themeansar, Wordpress-extensions | 2 Ansar Import – One Click Starter Sites – For Elementor & Themes, Ansar Import – One Click Starter Sites – For Elementor & Themes | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor & Themes <= 2.1.2 versions. | ||||
| CVE-2026-39780 | 2 Wordpress-extensions, Youzify | 2 Youzify, Youzify | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-39781 | 2 Dan Rossiter, Wordpress-extensions | 2 Document Gallery, Document Gallery | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | ||||
| CVE-2026-39784 | 2 Nicdark, Wordpress-extensions | 2 Hotel Booking, Hotel Booking | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. | ||||
| CVE-2026-39788 | 2 Shamimsplugins, Wordpress-extensions | 2 Front End Pm, Front End Pm | 2026-10-06 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions. | ||||
| CVE-2026-39790 | 2 E4jvikwp, Wordpress-extensions | 2 Vikrentcar, Vikrentcar | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. | ||||
| CVE-2026-40806 | 2 Plugin-devs, Wordpress-extensions | 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | ||||
| CVE-2026-40807 | 2 Aman, Wordpress-extensions | 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. | ||||
| CVE-2026-96594 | 2026-10-06 | N/A | ||
| The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions. | ||||
| CVE-2026-102161 | 2026-10-06 | 8.8 High | ||
| An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend. | ||||