Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Astro: Reflected XSS via unescaped slot name
Apache Atlas: Stored XSS in Create Entity page
Radware Cyber Controller HTML Report Generation HTML injection
Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
Apache Answer: HTML Content Injection in Email
Bolt CMS HTML Attribute TextType.php HTML injection
ScadaBR Unauthenticated Reflected Cross-Site Scripting
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
The GDPR cookies module for Backdrop CMS (before 1
CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output
Open WebUI: Stored Cross-Site Scripting in SVG Renderer
MapGeo - Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter
CVAT: Stored XSS via annotation guides
efw4.X: Stored XSS via previewServlet
Visual Studio Code Remote Code Execution Vulnerability
YAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
YAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution for All Thread Viewers
Showing 1 - 20 of 1,000+ results