Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40105 1 Concretecms 1 Concrete Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.
CVE-2021-40100 1 Concretecms 1 Concrete Cms 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
CVE-2021-40096 1 Squaredup 1 Squaredup 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.
CVE-2021-40094 1 Squaredup 1 Squaredup 2026-06-17 3.5 LOW 5.4 MEDIUM
A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.
CVE-2021-40093 1 Squaredup 1 Squaredup 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions.
CVE-2021-40092 1 Squaredup 1 Squaredup 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.
CVE-2021-40041 1 Huawei 2 Ws318n-21, Ws318n-21 Firmware 2026-06-17 1.9 LOW 4.2 MEDIUM
There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.
CVE-2021-3994 1 Django-helpdesk Project 1 Django-helpdesk 2026-06-17 6.8 MEDIUM 9.6 CRITICAL
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3988 1 Janeczku 1 Calibre-web 2026-06-17 N/A 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover or a format. The affected code directly inserts user input into the DOM without proper sanitization, allowing attackers to execute arbitrary JavaScript code. This can lead to various attacks, including stealing cookies. The issue is present in the code handling the `#btn-upload-cover` change event.
CVE-2021-3985 1 Kimai 1 Kimai2 2026-06-17 6.0 MEDIUM 9.0 CRITICAL
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3983 1 Kimai2 Project 1 Kimai2 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3977 1 Invoiceninja 1 Invoice Ninja 2026-06-17 3.5 LOW 5.4 MEDIUM
invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3961 1 Snipeitapp 1 Snipe-it 2026-06-17 3.5 LOW 5.4 MEDIUM
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3950 1 Django-helpdesk Project 1 Django-helpdesk 2026-06-17 3.5 LOW 5.4 MEDIUM
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3945 1 Django-helpdesk Project 1 Django-helpdesk 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3938 1 Snipeitapp 1 Snipe-it 2026-06-17 3.5 LOW 5.4 MEDIUM
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3920 1 Getgrav 1 Grav-plugin-admin 2026-06-17 3.5 LOW 5.4 MEDIUM
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3914 1 Redhat 3 Build Of Quarkus, Openshift Application Runtimes, Smallrye Health 2026-06-17 N/A 6.1 MEDIUM
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
CVE-2021-3904 1 Getgrav 1 Grav 2026-06-17 3.5 LOW 5.4 MEDIUM
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3879 1 Snipeitapp 1 Snipe-it 2026-06-17 3.5 LOW 5.4 MEDIUM
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')