Total
47191 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66690 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | |||||
| CVE-2026-66440 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | |||||
| CVE-2026-61961 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | |||||
| CVE-2026-65513 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | |||||
| CVE-2026-61963 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | |||||
| CVE-2026-65565 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | |||||
| CVE-2026-61964 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | |||||
| CVE-2026-66694 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | |||||
| CVE-2026-66663 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |||||
| CVE-2026-61959 | 2026-08-12 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | |||||
| CVE-2026-66457 | 2026-08-12 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | |||||
| CVE-2025-0152 | 1 Ibm | 1 Engineering Requirements Management Doors Web Access | 2026-08-12 | N/A | 6.1 MEDIUM |
| IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2026-9318 | 2026-08-12 | N/A | 5.4 MEDIUM | ||
| tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the _html.py format handler. Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser. | |||||
| CVE-2026-33167 | 1 Rubyonrails | 1 Rails | 2026-08-12 | N/A | 6.1 MEDIUM |
| Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch. | |||||
| CVE-2026-2072 | 1 Hitachi | 2 Infrastructure Analytics Advisor, Ops Center Analyzer | 2026-08-12 | N/A | 8.2 HIGH |
| Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |||||
| CVE-2026-70560 | 2026-08-12 | N/A | 5.4 MEDIUM | ||
| Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role such as Cashier can submit a leave request through the HRM/Leave module, causing the unsanitized first-name markup to execute in the browser session of any higher-privileged user who views the leave-application notification pane, enabling cross-user session compromise within the admin origin. | |||||
| CVE-2026-57105 | 1 Microsoft | 1 Sharepoint Server | 2026-08-12 | N/A | 8.0 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-64897 | 1 Microsoft | 1 Sharepoint Server | 2026-08-11 | N/A | 4.6 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-64902 | 1 Microsoft | 1 Sharepoint Server | 2026-08-11 | N/A | 4.6 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-62829 | 1 Microsoft | 1 Sharepoint Server | 2026-08-11 | N/A | 4.6 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |||||
