CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-77615 HIGH

Paella Player: Stored XSS via caption cue text

CVSS 8.7 EPSS 0.56% Sep 17, 2026
Mavennpm
CVE-2026-43871 HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit

CVSS 8.7 EPSS 1.03% Jul 27, 2026
GoMavenPackagistPyPI
CVE-2026-12866 CRITICAL

expr-eval: expr-eval: Code Execution via crafted expressions in toJSFunction() API

CVSS 9.2 EPSS 0.87% Jun 23, 2026
Mavennpm
CVE-2026-44503 HIGH

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

CVSS 7.0 EPSS 0.84% May 14, 2026
GoMavenNuGetPyPInpm
CVE-2026-45091 CRITICAL

sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)

CVSS 9.1 EPSS 0.40% May 12, 2026
Mavennpm
CVE-2026-2366 LOW

Keycloak: keycloak: information disclosure via authorization bypass in admin api

CVSS 3.1 EPSS 0.27% Mar 12, 2026
Mavennpm
CVE-2025-15104 MEDIUM

Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF

CVSS 6.9 EPSS 0.47% Jan 16, 2026
Mavennpm
CVE-2025-14874 HIGH

Nodemailer: nodemailer: denial of service via crafted email address header

CVSS 7.5 EPSS 0.56% Dec 18, 2025
Mavennpm
CVE-2025-68113 MEDIUM

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

CVSS 6.5 EPSS 0.46% Dec 16, 2025
GoHexMavenPackagistPyPIRubyGemsnpm
CVE-2025-11849 MEDIUM

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth b…

CVSS 6.4 EPSS 1.01% Oct 17, 2025
MavenNuGetPyPInpm
CVE-2025-43761 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 thro…

CVSS 6.9 EPSS 0.19% Aug 22, 2025
Mavennpm
CVE-2024-21534 CRITICAL

jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization

CVSS 9.3 EPSS 9.02% Oct 11, 2024
Mavennpm
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.20% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.09% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-35255 MEDIUM

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

CVSS 6.8 EPSS 0.83% Jun 11, 2024
GoMavenNuGetPyPInpm
CVE-2024-21490 HIGH

angular: Inefficient Regular Expression Complexity

CVSS 7.5 EPSS 1.89% Feb 10, 2024
Mavennpm
CVE-2023-26154 MEDIUM

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…

CVSS 5.9 EPSS 0.96% Dec 6, 2023
GoMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm
CVE-2023-44487 KEV MEDIUM

HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

CVSS 6.9 EPSS 100.00% Oct 10, 2023
GoMavenSwiftURL
CVE-2020-23064 MEDIUM

jquery: Cross-site scripting

CVSS 6.3 EPSS 0.04% Jun 26, 2023
MavenNuGetRubyGemsnpm
CVE-2023-34620 HIGH

An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic depende…

CVSS 7.5 EPSS 0.78% Jun 14, 2023
GoMavenPackagist
CVE-2022-25881 HIGH

http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

CVSS 7.5 EPSS 1.61% Jan 31, 2023
Mavennpm
CVE-2022-25901 HIGH

cookiejar: Regular Expression Denial of Service (ReDoS)

CVSS 7.5 EPSS 1.55% Jan 18, 2023
Mavennpm
CVE-2022-25940 HIGH

Denial of Service (DoS)

CVSS 7.5 EPSS 1.16% Dec 21, 2022
Mavennpm
CVE-2022-25873 MEDIUM

Cross-site Scripting (XSS)

CVSS 5.4 EPSS 0.85% Sep 18, 2022
Mavennpm
CVE-2020-7677 CRITICAL

Arbitrary Code Execution

CVSS 9.8 EPSS 2.02% Jul 25, 2022
Mavennpm

Showing 1 to 25 CVEs · page 1 (more available)