CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2022-31160 MEDIUM

jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label

CVSS 6.1 EPSS 2.64% Jul 20, 2022
MavenNuGetRubyGemsnpm
CVE-2021-41184 MEDIUM

XSS in the `of` option of the `.position()` util

CVSS 6.5 EPSS 40.77% Oct 26, 2021
MavenNuGetRubyGemsnpm
CVE-2021-41183 MEDIUM

XSS in `*Text` options of the Datepicker widget

CVSS 6.5 EPSS 8.53% Oct 26, 2021
MavenNuGetRubyGemsnpm
CVE-2021-41182 MEDIUM

XSS in the `altField` option of the Datepicker widget

CVSS 6.5 EPSS 39.36% Oct 26, 2021
MavenNuGetRubyGemsnpm
CVE-2020-7656 MEDIUM

jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces

CVSS 5.3 EPSS 6.27% May 19, 2020
MavenNuGetRubyGemsnpm
CVE-2020-11023 KEV MEDIUM

Potential XSS vulnerability in jQuery

CVSS 6.9 EPSS 84.89% Apr 29, 2020
MavenNuGetPackagistRubyGemsnpm
CVE-2020-11022 MEDIUM

jQuery has a potential XSS vulnerability

CVSS 6.9 EPSS 99.22% Apr 29, 2020
MavenNuGetPackagistRubyGemsnpm
CVE-2018-18405 MEDIUM

jquery: crafted onerror attribute of an IMG element could result in XSS

CVSS 6.1 EPSS 1.66% Apr 22, 2020
CVE-2019-11358 MEDIUM

jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection

CVSS 6.1 EPSS 86.82% Apr 19, 2019
MavenNuGetPackagistPyPIRubyGemsnpm
CVE-2016-10707 HIGH

jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased na…

CVSS 7.5 EPSS 2.89% Jan 18, 2018
MavenNuGetRubyGemsnpm
CVE-2015-9251 MEDIUM

jquery: Cross-site scripting via cross-domain ajax requests

CVSS 6.1 EPSS 29.73% Jan 18, 2018
MavenNuGetRubyGemsnpm
CVE-2012-6708 MEDIUM

js-jquery: XSS via improper selector detection

CVSS 6.8 EPSS 8.63% Jan 18, 2018
MavenNuGetRubyGemsnpm
CVE-2014-6071 MEDIUM

jQuery: cross-site scripting flaw

CVSS 6.1 EPSS 2.34% Jan 16, 2018
CVE-2011-4969 MEDIUM

jquery: Cross-site scripting (XSS) via $(location.hash) and $(#<tag>)

CVSS 4.3 EPSS 19.19% Mar 8, 2013
MavenNuGetRubyGemsnpm
CVE-2007-2379 MEDIUM

The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain th…

CVSS 5.0 EPSS 2.77% Apr 30, 2007

Showing 1 to 15 CVEs · page 1