CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-73426 MEDIUM

Trix: Stored XSS vulnerability through serialized attributes

CVSS 4.6 EPSS 0.32% Aug 18, 2026
RubyGemsnpm
CVE-2026-73428 MEDIUM

Trix: Stored XSS via HTMLParser attribute injection on paste

CVSS 4.6 EPSS 0.35% Aug 13, 2026
RubyGemsnpm
CVE-2026-73427 LOW

Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)

CVSS 2.1 EPSS 0.57% Aug 12, 2026
RubyGemsnpm
CVE-2026-4800 CRITICAL

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS 9.8 EPSS 2.62% Mar 31, 2026
RubyGemsnpm
CVE-2025-68113 MEDIUM

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

CVSS 6.5 EPSS 0.46% Dec 16, 2025
GoHexMavenPackagistPyPIRubyGemsnpm
CVE-2025-48069 MEDIUM

ejson2env has insufficient input sanitization

CVSS 6.6 EPSS 1.32% May 21, 2025
GoRubyGems
CVE-2024-47529 MEDIUM

OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)

CVSS 5.9 EPSS 0.35% Oct 2, 2024
PyPIRubyGemsnpm
CVE-2024-43795 MEDIUM

OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)

CVSS 5.1 EPSS 0.48% Oct 2, 2024
PyPIRubyGemsnpm
CVE-2024-46488 HIGH

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Se…

CVSS 8.8 EPSS 0.44% Sep 25, 2024
PyPIRubyGemscrates.ionpm
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.20% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…

CVSS n/a EPSS 0.09% Jul 11, 2024
MavenNuGetPackagistRubyGemsnpm
CVE-2024-34341 MEDIUM

The Trix Editor Contains an Arbitrary Code Execution Vulnerability

CVSS 5.4 EPSS 0.78% May 7, 2024
RubyGemsnpm
CVE-2024-28181 HIGH

Arbitrary method invocation turbo_boost-commands

CVSS 8.1 EPSS 0.80% Mar 14, 2024
RubyGemsnpm
CVE-2024-28121 HIGH

Reflex arbitrary method call in stimulus_reflex

CVSS 8.8 EPSS 1.55% Mar 12, 2024
RubyGemsnpm
CVE-2023-26154 MEDIUM

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…

CVSS 5.9 EPSS 0.96% Dec 6, 2023
GoMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm
CVE-2020-23064 MEDIUM

jquery: Cross-site scripting

CVSS 6.3 EPSS 0.04% Jun 26, 2023
MavenNuGetRubyGemsnpm
CVE-2022-31160 MEDIUM

jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label

CVSS 6.1 EPSS 2.64% Jul 20, 2022
MavenNuGetRubyGemsnpm
CVE-2021-41184 MEDIUM

XSS in the `of` option of the `.position()` util

CVSS 6.5 EPSS 40.77% Oct 26, 2021
MavenNuGetRubyGemsnpm
CVE-2021-41183 MEDIUM

XSS in `*Text` options of the Datepicker widget

CVSS 6.5 EPSS 8.53% Oct 26, 2021
MavenNuGetRubyGemsnpm
CVE-2021-41182 MEDIUM

XSS in the `altField` option of the Datepicker widget

CVSS 6.5 EPSS 39.36% Oct 26, 2021
MavenNuGetRubyGemsnpm
CVE-2021-23337 HIGH

Command Injection

CVSS 7.2 EPSS 21.33% Feb 15, 2021
RubyGemsnpm
CVE-2020-28500 MEDIUM

Regular Expression Denial of Service (ReDoS)

CVSS 5.3 EPSS 7.34% Feb 15, 2021
RubyGemsnpm
CVE-2020-8203 HIGH

nodejs-lodash: prototype pollution in zipObjectDeep function

CVSS 7.4 EPSS 5.21% Jul 15, 2020
RubyGemsnpm
CVE-2020-7656 MEDIUM

jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces

CVSS 5.3 EPSS 6.27% May 19, 2020
MavenNuGetRubyGemsnpm
CVE-2020-11023 KEV MEDIUM

Potential XSS vulnerability in jQuery

CVSS 6.9 EPSS 84.89% Apr 29, 2020
MavenNuGetPackagistRubyGemsnpm

Showing 1 to 25 CVEs · page 1 (more available)