Export limit exceeded: 401141 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 50016 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50016 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93977 | 1 Code-projects | 1 Assessment Management | 2026-09-24 | 3.5 Low |
| A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-94045 | 1 Newbee-ltd | 1 Newbee-mall | 2026-09-24 | 3.5 Low |
| A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argument goodsName results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. ImageIO.read() is a format-agnostic read - it returns non-null for a polyglot PNG|<img onerror> payload, which is exactly why the "image-only" guard is bypassable; the attacker-controlled suffix + /upload/** static mapping is what turns the upload into persisted XSS rather than a one-shot. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-94035 | 1 Sourcecodester | 1 Drug Recommendation System | 2026-09-24 | 4.3 Medium |
| A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-93622 | 2 Nicolaskulka, Wordpress | 2 Wps Limit Login, Wordpress | 2026-09-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions. | ||||
| CVE-2026-94118 | 2 Leap13, Wordpress | 2 Premium Blocks – Gutenberg Blocks For Wordpress, Wordpress | 2026-09-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. | ||||
| CVE-2026-94500 | 2 Roxnor, Wordpress | 2 Elementskit Elementor Addons Lite, Wordpress | 2026-09-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. | ||||
| CVE-2026-94176 | 2 Kitae-park, Wordpress | 2 Mang Board Wp, Wordpress | 2026-09-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. | ||||
| CVE-2026-93774 | 2 Jacob N. Breetvelt, Wordpress | 2 Wp Photo Album Plus, Wordpress | 2026-09-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. | ||||
| CVE-2026-94391 | 2 Rustaurius, Wordpress | 2 Ultimate Faq, Wordpress | 2026-09-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | ||||
| CVE-2026-94179 | 2 Razorpay, Wordpress | 2 Razorpay Payment Button, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. | ||||
| CVE-2026-94461 | 2 Metaphorcreations, Wordpress | 2 Ditty, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. | ||||
| CVE-2026-94680 | 2 Radiustheme, Wordpress | 2 The Post Grid, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | ||||
| CVE-2026-94671 | 2 Radiustheme, Wordpress | 2 The Post Grid, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | ||||
| CVE-2026-94682 | 2 Secondlinethemes, Wordpress | 2 Podcast Importer Secondline, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. | ||||
| CVE-2026-95529 | 2 Codepeople, Wordpress | 2 Calculated Fields Form, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | ||||
| CVE-2026-95515 | 2 Ninjaforms, Wordpress | 2 Ninja Forms, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||
| CVE-2026-77394 | 1 Openc3 | 1 Cosmos | 2026-09-23 | 7.6 High |
| OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by openc3-cosmos-init/plugins/packages/openc3-vue-common/src/widgets/ButtonWidget.vue in another operator's browser session when the button is activated. The stored script runs in the COSMOS origin and can read localStorage.openc3Token, allowing theft of the victim's bearer token, account takeover, and actions with the victim's privileges. The permissive content security policy contributes to execution but is not the primary root cause. This issue is fixed in version 7.3.0. | ||||
| CVE-2026-93526 | 2 Nexcess, Wordpress | 2 Event Tickets, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | ||||
| CVE-2026-18872 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 9.3 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions. | ||||
| CVE-2026-93772 | 2 Tomdever, Wordpress | 2 Wpforo Forum, Wordpress | 2026-09-23 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. | ||||