Export limit exceeded: 403884 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 50283 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50283 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103047 | 1 Wikimedia | 1 Mediawiki - Centralauth Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-103045 | 1 The Wikimedia Foundation | 1 Mediawiki - Refreshed Skin | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-100673 | 1 Getgrav | 1 Grav | 2026-09-30 | 8.2 High |
| The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5. | ||||
| CVE-2026-100245 | 2026-09-30 | 6.1 Medium | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-100243 | 2026-09-30 | 6.1 Medium | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS. This issue affects Mediawiki - WikiSEO Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-100238 | 2026-09-30 | 6.1 Medium | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-92994 | 2026-09-30 | 8.8 High | ||
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | ||||
| CVE-2026-76718 | 1 Hewlett Packard Enterprise | 1 Hpe Oneview | 2026-09-30 | 8.2 High |
| A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. | ||||
| CVE-2026-76719 | 1 Hewlett Packard Enterprise | 1 Hpe Oneview | 2026-09-30 | 8.2 High |
| A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. | ||||
| CVE-2026-100294 | 1 Anjvision | 1 Yssd-rtmp-h5 | 2026-09-30 | 7.5 High |
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation. | ||||
| CVE-2026-96587 | 1 Viidure | 1 Dashcam Android Application | 2026-09-30 | 10 Critical |
| The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries. | ||||
| CVE-2026-84409 | 1 Lantronix | 1 G520 Series | 2026-09-30 | 7.5 High |
| The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device. | ||||
| CVE-2026-71189 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 3.5 Low |
| An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. | ||||
| CVE-2026-102771 | 2 Naichen, Thinkcmf | 2 Thinkcmf, Thinkcmf | 2026-09-30 | 4.7 Medium |
| A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. The manipulation leads to improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-103050 | 1 Wikimedia | 1 Mediawiki - Massmessage Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-103051 | 1 Wikimedia | 1 Mediawiki - Centralnotice Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-92712 | 2 Rockiger, Wordpress-extensions | 2 Reactpress, Reactpress | 2026-09-30 | 6.4 Medium |
| The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents(). | ||||
| CVE-2026-102386 | 2 Jacob N. Breetvelt, Wordpress-extensions | 2 Wp Photo Album Plus, Wp Photo Album Plus | 2026-09-30 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | ||||
| CVE-2026-102395 | 2 Supsystic, Wordpress-extensions | 2 Easy Google Maps, Easy Google Maps | 2026-09-30 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | ||||
| CVE-2026-102396 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-09-30 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||