CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-50584
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the …

Oct 30, 2025
CVE-2021-47699
5.4 MEDIUM

Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form. Insufficient validation or escaping …

Oct 30, 2025
CVE-2021-47697
5.4 MEDIUM

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2021-47696
5.4 MEDIUM

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2021-47695
5.4 MEDIUM

Nagios XI versions prior to 5.8.0 are vulnerable to stored cross-site scripting (XSS) via the My Tools page. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2021-47694
6.1 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via …

Oct 30, 2025
CVE-2021-47691
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities via the …

Oct 30, 2025
CVE-2021-47690
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities in Overlay …

Oct 30, 2025
CVE-2021-47689
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting (XSS) vulnerability in the …

Oct 30, 2025
CVE-2020-36866
5.4 MEDIUM

Nagios XI versions prior to 5.7.3 are vulnerable to cross-site scripting (XSS) via the Manage Users page of the Admin interface. Insufficient validation or escaping …

Oct 30, 2025
CVE-2020-36865
5.4 MEDIUM

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. …

Oct 30, 2025
CVE-2020-36864
5.4 MEDIUM

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplied …

Oct 30, 2025
CVE-2020-36862
6.1 MEDIUM

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content …

Oct 30, 2025
CVE-2020-36861
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site scripting (XSS) vulnerabilities in the …

Oct 30, 2025
CVE-2020-36860
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site scripting (XSS) vulnerabilities in the …

Oct 30, 2025
CVE-2020-36858
5.4 MEDIUM

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host …

Oct 30, 2025
CVE-2018-25121
5.4 MEDIUM

Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2018-25119
6.1 MEDIUM

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow …

Oct 30, 2025
CVE-2017-20209
6.1 MEDIUM

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2016-15053
5.4 MEDIUM

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping …

Oct 30, 2025
CVE-2016-15052
5.4 MEDIUM

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2016-15051
5.4 MEDIUM

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient …

Oct 30, 2025
CVE-2016-15049
5.4 MEDIUM

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. …

Oct 30, 2025
CVE-2013-10074
5.4 MEDIUM

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2013-10072
6.5 MEDIUM

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages …

Oct 30, 2025
CVE-2013-10071
6.1 MEDIUM

Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2011-10040
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or …

Oct 30, 2025
CVE-2011-10039
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the web …

Oct 30, 2025
CVE-2011-10038
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping …

Oct 30, 2025
CVE-2011-10037
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web …

Oct 30, 2025
CVE-2011-10036
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2025-62265
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Oct 30, 2025
CVE-2025-57109
6.5 MEDIUM

Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string …

Oct 30, 2025
CVE-2025-52180
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of …

Oct 30, 2025
CVE-2025-52179
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of …

Oct 30, 2025
CVE-2025-64116
6.1 MEDIUM

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without …

Oct 30, 2025
CVE-2025-64115
6.1 MEDIUM

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header …

Oct 30, 2025
CVE-2025-62266
6.1 MEDIUM

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA …

Oct 30, 2025
CVE-2025-56313
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary …

Oct 30, 2025
CVE-2025-63885
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Oct 30, 2025
CVE-2025-60950
6.1 MEDIUM

An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to execute arbitrary code via a crafted SVG file.

Oct 30, 2025
CVE-2025-60319
6.5 MEDIUM

PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java).

Oct 30, 2025
CVE-2025-46363
4.3 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative Path Traversal vulnerability in the SCG exposed for an …

Oct 30, 2025
CVE-2025-36592
5.4 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') …

Oct 30, 2025
CVE-2025-12517
5.3 MEDIUM

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 30, 2025
CVE-2025-5347
6.3 MEDIUM

Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.

Oct 30, 2025
CVE-2025-5343
6.3 MEDIUM

Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

Oct 30, 2025
CVE-2025-5342
4.3 MEDIUM

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

Oct 30, 2025
CVE-2025-50574
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allows remote attackers to inject arbitrary web script or HTML via …

Oct 30, 2025
CVE-2025-50736
6.1 MEDIUM

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.