Export limit exceeded: 49137 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49137 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85577 | 1 Wwbn | 1 Avideo | 2026-09-04 | 5.4 Medium |
| AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page. | ||||
| CVE-2026-85382 | 1 Light0011 | 1 Cms | 2026-09-04 | 4.3 Medium |
| A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_decode of the file App/Home/View/Default/Chapter/oneChapter.tpl of the component Chapter Content Output. Performing a manipulation of the argument content results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-85149 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 5.3 Medium |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | ||||
| CVE-2026-85148 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 9.8 Critical |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | ||||
| CVE-2026-85146 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 9.8 Critical |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | ||||
| CVE-2026-85061 | 1 Maplibre | 1 Maplibre-gl-js | 2026-09-04 | 10 Critical |
| MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribute such as onload or ontoggle to survive sanitization and execute when the attribution control inserts the content into innerHTML. A victim must render the affected map content for the script to execute. This issue is fixed in version 6.4.1. | ||||
| CVE-2026-65644 | 1 Rocket.chat | 1 Rocket.chat | 2026-09-04 | 7.5 High |
| Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue. | ||||
| CVE-2026-77818 | 1 Yordam | 1 Library Information And Document Automation Program | 2026-09-04 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and Document Automation Program: from v22.1 before v22.2. | ||||
| CVE-2026-40986 | 2 Broadcom, Spring | 2 Spring Web Flow, Spring Web Flow | 2026-09-04 | 4.8 Medium |
| Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. | ||||
| CVE-2026-85541 | 1 Interinfo | 1 Dreammaker | 2026-09-04 | 5.4 Medium |
| DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website. | ||||
| CVE-2026-85405 | 1 Eleveo | 1 Call Recording Software | 2026-09-04 | 3.5 Low |
| A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument name/username can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2022-35497 | 1 Trimble | 1 Tm4web | 2026-09-04 | N/A |
| In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint. | ||||
| CVE-2026-5522 | 1 Ibm | 1 Qradar | 2026-09-04 | 6.7 Medium |
| IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | ||||
| CVE-2026-81282 | 2 Villatheme, Wordpress | 2 Product Variations Swatches For Woocommerce, Wordpress | 2026-09-04 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | ||||
| CVE-2026-81292 | 2 Ido Kobelkowsky, Wordpress | 2 Simple Payment, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | ||||
| CVE-2026-81300 | 2 Silverplugins217, Wordpress | 2 Calculation For Contact Form 7, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | ||||
| CVE-2026-81776 | 2 Advanpix, Wordpress | 2 Wp Quicklatex, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | ||||
| CVE-2026-84765 | 2 John Havlik, Wordpress | 2 Breadcrumb Navxt, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | ||||
| CVE-2026-84773 | 2 Wordpress, 作者 | 2 Wordpress, Shane Bishop:ewww Image Optimizer | 2026-09-04 | 7.2 High |
| Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | ||||
| CVE-2026-14466 | 1 Stormshield | 1 Stormshield Network Security | 2026-09-04 | 4.3 Medium |
| It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface. | ||||