CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
KaTeX: Existing prototype pollution can bypass trust restrictions
HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)
HCL BigFix Service Management is affected by multiple security vulnerabilities.
Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories
HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL iControl is affected by a Session Timeout vulnerability
HCL iControl is affected by a Missing Secure Attribute vulnerability
HCL iControl is affected by an Improper Error Handling vulnerability
Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation
Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name
Genians, Inc Genian SSL PNS Unrestricted File Upload
David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal
BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS
attacker-controlled javascript license URL via XSS
attacker-controlled javascript license URL via XSS
Kiteworks Core Server-Side Request Forgery (SSRF)
pagetriagelist discloses suppressed reviewer usernames
Various rawParams() and escaped() updates to prevent XSS in Wikibase extension
Various rawParams() and escaped() updates to prevent XSS in Wikistories extension
ReadingLists imported metadata permits JavaScript URL XSS
Stored XSS through PageForms #autoedit redirect links
Stored XSS through system messages in WikiForum
API permits session-seeded javascript URL XSS
Showing 1 to 25 CVEs · page 1 (more available)