CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-53598 HIGH

Prompty: Arbitrary File Read via ${file:path} Reference Expansion

CVSS 7.5 EPSS 1.29% Jul 16, 2026
NuGetPyPIcrates.ionpm
CVE-2026-47762 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

CVSS 8.7 EPSS 0.42% May 28, 2026
NuGetPackagistnpm
CVE-2026-47761 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

CVSS 8.7 EPSS 0.41% May 28, 2026
NuGetPackagistnpm
CVE-2026-47759 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

CVSS 8.7 EPSS 0.42% May 28, 2026
NuGetPackagistnpm
CVE-2026-47760 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

CVSS 8.7 EPSS 0.27% May 28, 2026
NuGetPackagistnpm
CVE-2026-44503 HIGH

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

CVSS 7.0 EPSS 0.84% May 14, 2026
GoMavenNuGetPyPInpm
CVE-2026-26118 HIGH

Azure MCP Server Tools Elevation of Privilege Vulnerability

CVSS 8.8 EPSS 0.86% Mar 10, 2026
NuGetPyPInpm
CVE-2025-11849 MEDIUM

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth b…

CVSS 6.4 EPSS 1.01% Oct 17, 2025
MavenNuGetPyPInpm
CVE-2025-24012 MEDIUM

Umbraco Backoffice Components Have XSS/HTML Injection Vulnerability

CVSS 5.4 EPSS 0.27% Jan 21, 2025
NuGetnpm
CVE-2024-47819 HIGH

Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section

CVSS 8.7 EPSS 0.35% Oct 22, 2024
NuGetnpm
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.20% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.09% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-38357 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

CVSS 5.3 EPSS 0.53% Jun 19, 2024
NuGetPackagistPyPInpm
CVE-2024-38356 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

CVSS 5.3 EPSS 0.53% Jun 19, 2024
NuGetPackagistPyPInpm
CVE-2024-35255 MEDIUM

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

CVSS 6.8 EPSS 0.83% Jun 11, 2024
GoMavenNuGetPyPInpm
CVE-2024-29881 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

CVSS 6.1 EPSS 0.71% Mar 26, 2024
NuGetPackagistnpm
CVE-2024-29203 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

CVSS 6.1 EPSS 0.71% Mar 26, 2024
NuGetPackagistnpm
CVE-2024-26318 MEDIUM

Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.

CVSS 6.1 EPSS 0.39% Feb 19, 2024
NuGetnpm
CVE-2024-21911 MEDIUM

Cross-site scripting vulnerability in TinyMCE

CVSS 6.1 EPSS 1.17% Jan 3, 2024
NuGetPackagistnpm
CVE-2024-21910 MEDIUM

Cross-site scripting vulnerability in TinyMCE plugins

CVSS 6.1 EPSS 0.96% Jan 3, 2024
NuGetPackagistPyPInpm
CVE-2024-21908 MEDIUM

Cross-site scripting vulnerability in TinyMCE

CVSS 6.1 EPSS 1.07% Jan 3, 2024
NuGetPackagistnpm
CVE-2023-26154 MEDIUM

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…

CVSS 5.9 EPSS 0.96% Dec 6, 2023
GoMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm
CVE-2023-48219 MEDIUM

Special characters in unescaped text nodes can trigger mXSS in TinyMCE

CVSS 6.1 EPSS 0.71% Nov 15, 2023
NuGetPackagistnpm
CVE-2023-45818 MEDIUM

Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin

CVSS 6.1 EPSS 0.62% Oct 19, 2023
NuGetPackagistnpm
CVE-2023-45819 MEDIUM

Cross-site Scripting vulnerability in TinyMCE notificationManager.open API

CVSS 6.1 EPSS 0.60% Oct 19, 2023
NuGetPackagistnpm

Showing 1 to 25 CVEs · page 1 (more available)