Total
47475 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-33332 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portlet_configuration_css_web_portlet_PortletConfigurationCSSPortlet_portletResource parameter. | |||||
| CVE-2021-33328 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter. | |||||
| CVE-2021-33326 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window. | |||||
| CVE-2021-33295 | 1 Joplin Project | 1 Joplin | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html. | |||||
| CVE-2021-33212 | 1 Element-it | 1 Http Commander | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SVG image. | |||||
| CVE-2021-33192 | 1 Apache | 1 Jena Fuseki | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive). | |||||
| CVE-2021-33179 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload. | |||||
| CVE-2021-33041 | 1 Vmd Project | 1 Vmd | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS. | |||||
| CVE-2021-33040 | 1 Futurepress | 1 Epub.js | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS. | |||||
| CVE-2021-33025 | 1 Xarrow | 1 Xarrow | 2026-06-17 | 4.6 MEDIUM | 5.6 MEDIUM |
| xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges. | |||||
| CVE-2021-33021 | 1 Xarrow | 1 Xarrow | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code. | |||||
| CVE-2021-33001 | 1 Xarrow | 1 Xarrow | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code. | |||||
| CVE-2021-32989 | 1 Lcds | 1 Laquis Scada | 2026-06-17 | 4.3 MEDIUM | 9.3 CRITICAL |
| When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting. | |||||
| CVE-2021-32962 | 1 Aggsoft | 1 Webserver | 2026-06-17 | 4.3 MEDIUM | 8.2 HIGH |
| The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code. | |||||
| CVE-2021-32927 | 1 Uffizio | 1 Gps Tracker | 2026-06-17 | 4.3 MEDIUM | 7.1 HIGH |
| An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker. | |||||
| CVE-2021-32862 | 2 Debian, Jupyter | 2 Debian Linux, Nbconvert | 2026-06-17 | N/A | 7.5 HIGH |
| The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer). | |||||
| CVE-2021-32860 | 1 Izimodal Project | 1 Izimodal | 2026-06-17 | N/A | 6.1 MEDIUM |
| iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field `title` when creating a `iziModal` instance is able to supply arbitrary `html` or `javascript` code that will be rendered in the context of a user, potentially leading to `XSS`. Version 1.6.1 contains a patch for this issue | |||||
| CVE-2021-32859 | 1 Baremetrics | 1 Date Range Picker | 2026-06-17 | N/A | 6.1 MEDIUM |
| The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the field `placeholder` when creating a `Calendar` instance is able to supply arbitrary `html` or `javascript` that will be rendered in the context of a user leading to XSS. There are no known patches for this issue. | |||||
| CVE-2021-32858 | 1 Esdoc | 1 Esdoc-publish-html-plugin | 2026-06-17 | N/A | 6.1 MEDIUM |
| esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-html-plugin 1.1.2 and prior can be bypassed which may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | |||||
| CVE-2021-32857 | 1 Agentejo | 1 Cockpit | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | |||||
