CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-54593 HIGH

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

CVSS 8.1 EPSS 0.68% Jul 28, 2026
GoPackagist
CVE-2026-43871 HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit

CVSS 8.7 EPSS 1.03% Jul 27, 2026
GoMavenPackagistPyPI
CVE-2026-47762 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

CVSS 8.7 EPSS 0.42% May 28, 2026
NuGetPackagistnpm
CVE-2026-47761 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

CVSS 8.7 EPSS 0.41% May 28, 2026
NuGetPackagistnpm
CVE-2026-47759 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

CVSS 8.7 EPSS 0.42% May 28, 2026
NuGetPackagistnpm
CVE-2026-47760 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

CVSS 8.7 EPSS 0.27% May 28, 2026
NuGetPackagistnpm
CVE-2025-68954 HIGH

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

CVSS 7.5 EPSS 0.24% Jan 6, 2026
GoPackagist
CVE-2025-68113 MEDIUM

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

CVSS 6.5 EPSS 0.46% Dec 16, 2025
GoHexMavenPackagistPyPIRubyGemsnpm
CVE-2025-54378 HIGH

HAX CMS Backend Lacks Comprehensive Authorization Checks

CVSS 8.3 EPSS 0.50% Jul 26, 2025
Packagistnpm
CVE-2025-54139 MEDIUM

HAX CMS' application pages are vulnerable to clickjacking

CVSS 6.1 EPSS 0.31% Jul 22, 2025
Packagistnpm
CVE-2024-51434 MEDIUM

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

CVSS 6.1 EPSS 0.35% Nov 7, 2024
Packagistnpm
CVE-2024-43407 MEDIUM

Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability

CVSS 5.3 EPSS 0.45% Aug 21, 2024
Packagistnpm
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.20% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.09% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-38357 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

CVSS 5.3 EPSS 0.53% Jun 19, 2024
NuGetPackagistPyPInpm
CVE-2024-38356 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

CVSS 5.3 EPSS 0.53% Jun 19, 2024
NuGetPackagistPyPInpm
CVE-2024-29881 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

CVSS 6.1 EPSS 0.71% Mar 26, 2024
NuGetPackagistnpm
CVE-2024-29203 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

CVSS 6.1 EPSS 0.71% Mar 26, 2024
NuGetPackagistnpm
CVE-2024-24815 MEDIUM

CKEditor4 Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection

CVSS 6.1 EPSS 0.71% Feb 7, 2024
Packagistnpm
CVE-2024-21911 MEDIUM

Cross-site scripting vulnerability in TinyMCE

CVSS 6.1 EPSS 1.17% Jan 3, 2024
NuGetPackagistnpm
CVE-2024-21910 MEDIUM

Cross-site scripting vulnerability in TinyMCE plugins

CVSS 6.1 EPSS 0.96% Jan 3, 2024
NuGetPackagistPyPInpm
CVE-2024-21908 MEDIUM

Cross-site scripting vulnerability in TinyMCE

CVSS 6.1 EPSS 1.07% Jan 3, 2024
NuGetPackagistnpm
CVE-2023-46308 CRITICAL

In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

CVSS 9.8 EPSS 0.94% Jan 3, 2024
Packagistnpm
CVE-2023-26154 MEDIUM

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…

CVSS 5.9 EPSS 0.96% Dec 6, 2023
GoMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm
CVE-2023-48219 MEDIUM

Special characters in unescaped text nodes can trigger mXSS in TinyMCE

CVSS 6.1 EPSS 0.71% Nov 15, 2023
NuGetPackagistnpm

Showing 1 to 25 CVEs · page 1 (more available)