Vulnerabilities (CVE)

Filtered by CWE-79
Total 47193 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38188 1 Microsoft 1 Azure Hdinsight 2026-08-10 N/A 4.5 MEDIUM
Azure Apache Hadoop Spoofing Vulnerability
CVE-2023-36881 1 Microsoft 1 Azure Hdinsight 2026-08-10 N/A 4.5 MEDIUM
Azure Apache Ambari Spoofing Vulnerability
CVE-2023-36877 1 Microsoft 1 Azure Hdinsight 2026-08-10 N/A 4.5 MEDIUM
Azure Apache Oozie Spoofing Vulnerability
CVE-2023-36869 1 Microsoft 1 Azure Devops Server 2026-08-10 N/A 6.3 MEDIUM
Azure DevOps Server Spoofing Vulnerability
CVE-2023-35394 1 Microsoft 1 Azure Hdinsight 2026-08-10 N/A 4.6 MEDIUM
Azure HDInsight Jupyter Notebook Spoofing Vulnerability
CVE-2023-35393 1 Microsoft 1 Azure Hdinsight 2026-08-10 N/A 4.5 MEDIUM
Azure Apache Hive Spoofing Vulnerability
CVE-2021-40440 1 Microsoft 1 Dynamics 365 Business Central 2026-08-10 3.5 LOW 5.4 MEDIUM
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-36950 1 Microsoft 1 Dynamics 365 2026-08-10 3.5 LOW 5.4 MEDIUM
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2021-36946 1 Microsoft 2 Dynamics 365 Business Central, Dynamics Nav 2026-08-10 3.5 LOW 5.4 MEDIUM
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2026-17734 1 Google 1 Chrome 2026-08-10 N/A 5.4 MEDIUM
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17728 1 Google 1 Chrome 2026-08-10 N/A 5.4 MEDIUM
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-55746 2026-08-10 N/A 7.6 HIGH
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so an authenticated user can store HTML/JavaScript in a folder title.
CVE-2026-31845 2026-08-10 6.4 MEDIUM 9.3 CRITICAL
A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without proper sanitization, output encoding, or content-type restrictions.
CVE-2025-6946 1 Watchguard 28 Firebox M270, Firebox M290, Firebox M370 and 25 more 2026-08-08 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.
CVE-2025-4805 2026-08-08 N/A N/A
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
CVE-2025-4804 2026-08-08 N/A N/A
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.
CVE-2025-1239 2026-08-08 N/A N/A
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
CVE-2025-6947 2026-08-08 N/A N/A
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
CVE-2025-1071 1 Watchguard 28 Firebox M270, Firebox M290, Firebox M370 and 25 more 2026-08-08 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
CVE-2026-70332 1 Microsoft 1 Sharepoint Online 2026-08-07 N/A 9.6 CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.