Total
45428 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-9024 | 2026-07-22 | N/A | 8.7 HIGH | ||
| A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session. | |||||
| CVE-2026-42678 | 2026-07-22 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5. | |||||
| CVE-2026-9309 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A | 5.4 MEDIUM |
| Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2. | |||||
| CVE-2026-10245 | 2026-07-22 | 4.0 MEDIUM | 3.5 LOW | ||
| A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. | |||||
| CVE-2026-10173 | 2026-07-22 | 5.0 MEDIUM | 4.3 MEDIUM | ||
| A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 21f78ce5da668bf5233efcd1896ec7c6e3b22eae. Applying a patch is the recommended action to fix this issue. | |||||
| CVE-2026-9308 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A | 5.4 MEDIUM |
| Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2. | |||||
| CVE-2026-10244 | 2026-07-22 | 4.0 MEDIUM | 3.5 LOW | ||
| A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. | |||||
| CVE-2026-10228 | 2026-07-22 | 4.0 MEDIUM | 3.5 LOW | ||
| A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of the argument Message results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-42681 | 2026-07-22 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14. | |||||
| CVE-2026-48559 | 2026-07-22 | N/A | 5.4 MEDIUM | ||
| Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp. | |||||
| CVE-2026-49375 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 6.1 MEDIUM |
| In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | |||||
| CVE-2026-49381 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 3.4 LOW |
| In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | |||||
| CVE-2026-10112 | 2026-07-22 | 3.3 LOW | 2.4 LOW | ||
| A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-49384 | 1 Jetbrains | 1 Pycharm | 2026-07-22 | N/A | 6.1 MEDIUM |
| In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible | |||||
| CVE-2026-34127 | 1 Tp-link | 2 Tl-sg108pe, Tl-sg108pe Firmware | 2026-07-22 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script into the device configuration, which may be stored and executed in the administrator’s browser when the affected interface is viewed. Successful exploitation may allow session cookie theft, unauthorized configuration changes, or access to sensitive information exposed through the management interface. | |||||
| CVE-2026-45668 | 2026-07-22 | N/A | N/A | ||
| Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type: launcher) with a #docName label that uses ../ path traversal to point at the payload note's API endpoint. The desktop client Electron renderer runs with nodeIntegration enabled, so an RCE is triggered once the payload is executed. This vulnerability is fixed in 0.102.2. | |||||
| CVE-2026-49371 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 7.1 HIGH |
| In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | |||||
| CVE-2026-49368 | 1 Jetbrains | 1 Youtrack | 2026-07-22 | N/A | 8.7 HIGH |
| In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | |||||
| CVE-2026-44651 | 2026-07-22 | N/A | N/A | ||
| SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends: res.status(500).send('Error occurred while trying to proxy to: ' + url + ' ' + error). The url value is attacker-controlled (req.params.url) and is not HTML-escaped before rendering. This vulnerability is fixed in 1.18.0. | |||||
| CVE-2026-45138 | 2026-07-21 | N/A | 5.4 MEDIUM | ||
| CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently discarded. The Blog controller writes `$lanData['content']` directly into `blog_langs.content`, and the public template echoes it without escaping — yielding stored XSS executable in any visitor's browser, including the superadmin when previewing or editing posts. Version 0.31.9.0 patches the issue. | |||||
