CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
HAX CMS Backend Lacks Comprehensive Authorization Checks
HAX CMS' application pages are vulnerable to clickjacking
Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.
Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes
CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection
Cross-site scripting vulnerability in TinyMCE
Cross-site scripting vulnerability in TinyMCE plugins
Cross-site scripting vulnerability in TinyMCE
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…
Special characters in unescaped text nodes can trigger mXSS in TinyMCE
Showing 1 to 25 CVEs · page 1 (more available)