Total
45310 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-57684 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions. | |||||
| CVE-2026-57671 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions. | |||||
| CVE-2026-27402 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions. | |||||
| CVE-2025-69152 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. | |||||
| CVE-2026-57755 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | |||||
| CVE-2026-57762 | 2026-07-02 | N/A | 5.9 MEDIUM | ||
| Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. | |||||
| CVE-2026-57678 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16. | |||||
| CVE-2026-57670 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions. | |||||
| CVE-2026-27425 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions. | |||||
| CVE-2026-57358 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions. | |||||
| CVE-2026-57763 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. | |||||
| CVE-2026-57359 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions. | |||||
| CVE-2026-57737 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16. | |||||
| CVE-2026-32208 | 1 Microsoft | 1 Edge Chromium | 2026-07-01 | N/A | 8.8 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-14000 | 1 Google | 1 Chrome | 2026-07-01 | N/A | 6.1 MEDIUM |
| Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14001 | 1 Google | 1 Chrome | 2026-07-01 | N/A | 6.1 MEDIUM |
| Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-50040 | 2026-07-01 | N/A | 6.1 MEDIUM | ||
| Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. | |||||
| CVE-2026-14068 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-01 | N/A | 6.1 MEDIUM |
| Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-6283 | 2026-07-01 | N/A | 5.4 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1. | |||||
| CVE-2026-5220 | 2026-07-01 | N/A | 6.4 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1. | |||||
