Export limit exceeded: 395618 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49415 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61597 | 1 Djust-org | 1 Djust | 2026-09-17 | N/A |
| djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments. | ||||
| CVE-2026-76704 | 1 Hewlett Packard Enterprise (hpe) | 1 Edgeconnect Sd-wan Gateways | 2026-09-17 | 5.5 Medium |
| A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application. | ||||
| CVE-2026-66890 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 9.6 Critical |
| The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. | ||||
| CVE-2026-68950 | 1 Digital Watchdog | 5 Va1g4 Recorder, Vg4 Recorder, Vmax A1 G4 Dvr and 2 more | 2026-09-17 | 8.8 High |
| The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. | ||||
| CVE-2026-76858 | 1 Netcore | 1 Nr255-v | 2026-09-17 | 4.8 Medium |
| Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, leading to persistent execution when the affected page is viewed. | ||||
| CVE-2026-76867 | 1 Netcore | 1 Nr255-v | 2026-09-17 | 5.4 Medium |
| Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers can inject persistent script payloads through these route and NAT configuration pages, which are then executed in the context of users viewing the affected pages. | ||||
| CVE-2026-76872 | 1 Netcore | 1 Nr255-v | 2026-09-17 | 5.4 Medium |
| Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attackers can inject persistent malicious scripts through these components to compromise the web management interface for other users.' | ||||
| CVE-2026-76873 | 1 Netcore | 1 Nr255-v | 2026-09-17 | 5.2 Medium |
| Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malicious script through these hostname fields, which is later rendered by network_config.js and network_security.js in the web management interface. | ||||
| CVE-2026-92257 | 1 Netcore | 1 Nr255-v | 2026-09-17 | 5.4 Medium |
| Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content. | ||||
| CVE-2026-11996 | 2 Codesupplyco, Wordpress | 2 Advanced Popups, Wordpress | 2026-09-17 | 6.4 Medium |
| The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2025-63842 | 1 Repetico | 1 Web Backend | 2026-09-17 | 5.4 Medium |
| A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field. | ||||
| CVE-2024-23176 | 1 Mediawiki | 1 Massmessage | 2026-09-17 | 5.4 Medium |
| An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS. | ||||
| CVE-2026-82767 | 1 Contec | 1 Sga1000 | 2026-09-17 | 5.2 Medium |
| Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82769 | 1 Contec | 4 Rp-wah-sr1, Rp-wah-sr12, Rp-wah-sr2 and 1 more | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82771 | 1 Contec | 3 Ece1000, Ece1020, Ecs1020 | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82773 | 1 Contec | 4 M2m Controller Configurable Type Cps-mcs341*, M2m Controller Integrated Type Cps-mc341, M2m Gateway Configurable Type Cps-mgs341* and 1 more | 2026-09-17 | 6.1 Medium |
| Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82776 | 1 Contec | 2 Configurable Type Cps-pcs341-ds1-1201, Integrated Type Cps-pc341-*-9201 | 2026-09-17 | 6.1 Medium |
| Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82781 | 1 Contec | 3 Programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041, Remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1, Remote I/o Coupler Unit (server Type) Cpsn-mcb271-* | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82788 | 1 Contec | 1 Cpsl-08p1en | 2026-09-17 | 6.1 Medium |
| Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82763 | 1 Contec | 14 Fxa3000, Fxa3020, Fxa3200 and 11 more | 2026-09-17 | 5.4 Medium |
| Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||