Total
44422 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-34799 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34800 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34801 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34802 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34803 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34804 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34805 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34806 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34807 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-3107 | 1 Teampass | 1 Teampass | 2026-04-07 | N/A | 5.4 MEDIUM |
| Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicious JavaScript payloads to be persistently stored in the database. When other users view the imported passwords, the payload is automatically executed in their browsers, resulting in a stored XSS condition at the endpoint 'redacted/index.php?page=items'. Exploiting this vulnerability allows an attacker to execute arbitrary JavaScript code in the context of multiple users and the administrator, which can lead to session hijacking, credential theft, privilege abuse, and compromise of application integrity. | |||||
| CVE-2026-3106 | 1 Teampass | 1 Teampass | 2026-04-07 | N/A | 5.4 MEDIUM |
| Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseƱa' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in the username field. As a result, arbitrary JavaScript code is automatically executed in the administrator's browser when viewing failed login entries, resulting in a blind XSS condition. | |||||
| CVE-2025-41357 | 1 Anonproxyserver | 1 Anon Proxy Server | 2026-04-07 | N/A | 6.1 MEDIUM |
| Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'host' parameter in '/diagdns.php' endpoint. | |||||
| CVE-2025-41356 | 1 Anonproxyserver | 1 Anon Proxy Server | 2026-04-07 | N/A | 6.1 MEDIUM |
| Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'host' parameter in '/diagconnect.php' endpoint. | |||||
| CVE-2025-41355 | 1 Anonproxyserver | 1 Anon Proxy Server | 2026-04-07 | N/A | 6.1 MEDIUM |
| Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'port' and 'proxyPort' parameters in '/anon.php' endpoint. | |||||
| CVE-2026-34729 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-04-07 | N/A | 6.1 MEDIUM |
| phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been patched in version 4.1.1. | |||||
| CVE-2026-34808 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34809 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34810 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34811 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
| CVE-2026-34818 | 1 Endian | 1 Firewall Community | 2026-04-07 | N/A | 6.4 MEDIUM |
| Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |||||
