Vulnerabilities (CVE)

Filtered by CWE-79
Total 47193 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-34089 1 Wikimedia 1 Scribunto 2026-08-11 N/A 7.5 HIGH
Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.
CVE-2026-31981 1 Nozominetworks 2 Cmc, Guardian 2026-08-11 N/A 5.9 MEDIUM
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
CVE-2026-23573 1 Fortinet 3 Fortios, Fortipam, Fortiproxy 2026-08-11 N/A 6.1 MEDIUM
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.
CVE-2026-0279 1 Paloaltonetworks 1 Pan-os 2026-08-11 N/A 6.1 MEDIUM
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.
CVE-2026-34495 1 Johnsoncontrols 1 Fms Employee 2026-08-10 N/A 5.4 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.
CVE-2026-3343 1 Watchguard 37 Firebox M270, Firebox M290, Firebox M295 and 34 more 2026-08-10 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.
CVE-2025-13939 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.
CVE-2025-13938 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.
CVE-2025-13937 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.
CVE-2025-13936 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.
CVE-2024-43476 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38221 1 Microsoft 1 Edge Chromium 2026-08-10 N/A 4.3 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-21396 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-21395 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 8.2 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21394 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Dynamics 365 Field Service Spoofing Vulnerability
CVE-2024-21393 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21389 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21328 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-21327 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
CVE-2024-20679 1 Microsoft 1 Azure Stack Hub 2026-08-10 N/A 6.5 MEDIUM
Azure Stack Hub Spoofing Vulnerability