Total
45542 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-47995 | 1 Adobe | 4 Commerce, Commerce B2b, I\/o Events and 1 more | 2026-07-29 | N/A | 8.1 HIGH |
| Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | |||||
| CVE-2023-46734 | 3 Debian, Sensiolabs, Symfony | 3 Debian Linux, Symfony, Twig-bridge | 2026-07-29 | N/A | 6.1 MEDIUM |
| Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters. | |||||
| CVE-2025-12799 | 2026-07-29 | N/A | 6.5 MEDIUM | ||
| A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling. | |||||
| CVE-2026-54498 | 1 Viewcomponent | 1 View Component | 2026-07-29 | N/A | 8.7 HIGH |
| view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream applications use around_render to wrap, replace, instrument, or conditionally return content that includes user-controlled data, and ViewComponent::Collection#render_in can amplify the issue by joining per-item results and marking the entire output html_safe, converting raw unsafe output into an ActiveSupport::SafeBuffer. This issue is fixed in version 4.12.0. | |||||
| CVE-2024-3822 | 1 Mranderson | 1 Base64 Encoder\/decoder | 2026-07-29 | N/A | 4.8 MEDIUM |
| The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
| CVE-2026-60664 | 1 Oracle | 1 Webcenter Content | 2026-07-29 | N/A | 8.8 HIGH |
| Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). | |||||
| CVE-2026-47631 | 1 Microsoft | 2 Exchange Server, Exchange Server Subscription Edition | 2026-07-28 | N/A | 8.1 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-45501 | 1 Microsoft | 2 Exchange Server, Exchange Server Subscription Edition | 2026-07-28 | N/A | 6.5 MEDIUM |
| Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-45500 | 1 Microsoft | 2 Exchange Server, Exchange Server Subscription Edition | 2026-07-28 | N/A | 6.1 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66030 | 2026-07-28 | N/A | 5.4 MEDIUM | ||
| Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized. | |||||
| CVE-2026-66031 | 2026-07-28 | N/A | 5.4 MEDIUM | ||
| Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Support Ticket detail page. | |||||
| CVE-2026-65882 | 2026-07-28 | N/A | 6.1 MEDIUM | ||
| Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector. | |||||
| CVE-2026-64810 | 1 Jetbrains | 1 Intellij Idea | 2026-07-28 | N/A | 4.3 MEDIUM |
| In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | |||||
| CVE-2026-51565 | 2026-07-28 | N/A | 6.1 MEDIUM | ||
| Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request | |||||
| CVE-2026-65448 | 2026-07-28 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | |||||
| CVE-2026-65446 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | |||||
| CVE-2026-65441 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | |||||
| CVE-2026-65439 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | |||||
| CVE-2026-59727 | 2026-07-28 | N/A | N/A | ||
| Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4. | |||||
| CVE-2026-61957 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | |||||
