CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Prompty: Arbitrary File Read via ${file:path} Reference Expansion
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
Azure MCP Server Tools Elevation of Privilege Vulnerability
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth b…
Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability
Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes
Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.
Cross-site scripting vulnerability in TinyMCE
Cross-site scripting vulnerability in TinyMCE plugins
Cross-site scripting vulnerability in TinyMCE
Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…
Special characters in unescaped text nodes can trigger mXSS in TinyMCE
Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin
Cross-site Scripting vulnerability in TinyMCE notificationManager.open API
Showing 1 to 25 CVEs · page 1 (more available)