CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Trix: Stored XSS vulnerability through serialized attributes
Trix: Stored XSS via HTMLParser attribute injection on paste
Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)
lodash vulnerable to Code Injection via `_.template` imports key names
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
ejson2env has insufficient input sanitization
OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)
OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)
sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Se…
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
The Trix Editor Contains an Arbitrary Code Execution Vulnerability
Arbitrary method invocation turbo_boost-commands
Reflex arbitrary method call in stimulus_reflex
Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…
jquery: Cross-site scripting
jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label
XSS in the `of` option of the `.position()` util
XSS in `*Text` options of the Datepicker widget
XSS in the `altField` option of the Datepicker widget
Command Injection
Regular Expression Denial of Service (ReDoS)
nodejs-lodash: prototype pollution in zipObjectDeep function
jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
Potential XSS vulnerability in jQuery
Showing 1 to 25 CVEs · page 1 (more available)