Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: javascript Clear
ID Title
CVE-2026-74938 Vulnerability in mozilla (CVE-2026-74938)
vulnerability in mozilla (CVE-2026-74938). Confidential information can be exposed externally.
CVE-2026-74937 Use-After-Free in mozilla (CVE-2026-74937)
vulnerability in mozilla (CVE-2026-74937). Successful exploitation can lead to full system takeover.
CVE-2026-74936 Use-After-Free in mozilla (CVE-2026-74936)
vulnerability in mozilla (CVE-2026-74936). Successful exploitation can lead to full system takeover.
CVE-2026-23938 Vulnerability in dos (CVE-2026-23938)
vulnerability in dos (CVE-2026-23938). Risk of unauthorized operations or information disclosure.
CVE-2026-23935 Out-of-Bounds Read in CVE-2026-23935 (CVE-2026-23935)
vulnerability in CVE-2026-23935 (CVE-2026-23935). Risk of unauthorized operations or information disclosure.
CVE-2026-75843 Privilege Escalation in CVE-2026-75843 (CVE-2026-75843)
vulnerability in CVE-2026-75843 (CVE-2026-75843). Successful exploitation can lead to full system takeover.
CVE-2026-75851 Privilege Escalation in CVE-2026-75851 (CVE-2026-75851)
vulnerability in CVE-2026-75851 (CVE-2026-75851). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `26.8.1` or later.
CVE-2026-75831 Cross-Site Scripting (XSS) in CVE-2026-75831 (CVE-2026-75831)
cross-site scripting in CVE-2026-75831 (CVE-2026-75831). Confidential information can be exposed externally.
CVE-2026-75840 Vulnerability in CVE-2026-75840 (CVE-2026-75840)
vulnerability in CVE-2026-75840 (CVE-2026-75840). Confidential information can be exposed externally.
CVE-2026-75834 Cross-Site Scripting (XSS) in CVE-2026-75834 (CVE-2026-75834)
cross-site scripting in CVE-2026-75834 (CVE-2026-75834). Risk of unauthorized operations or information disclosure.
CVE-2026-75107 Cross-Site Scripting (XSS) in CVE-2026-75107 (CVE-2026-75107)
cross-site scripting in CVE-2026-75107 (CVE-2026-75107). Risk of unauthorized operations or information disclosure.
CVE-2026-15371 Vulnerability in CVE-2026-15371 (CVE-2026-15371)
vulnerability in CVE-2026-15371 (CVE-2026-15371). Confidential information can be exposed externally.
CVE-2026-56677 Vulnerability in 9router (CVE-2026-56677)
vulnerability in 9router (CVE-2026-56677). Data can be tampered with by attackers. Exploitable via `POST /api/auth/oidc/test`.
CVE-2026-75531 Cross-Site Scripting (XSS) in CVE-2026-75531 (CVE-2026-75531)
cross-site scripting in CVE-2026-75531 (CVE-2026-75531). Risk of unauthorized operations or information disclosure.
CVE-2026-74234 Vulnerability in CVE-2026-74234 (CVE-2026-74234)
vulnerability in CVE-2026-74234 (CVE-2026-74234). Confidential information can be exposed externally.
CVE-2026-71553 Vulnerability in dos (CVE-2026-71553)
vulnerability in dos (CVE-2026-71553). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v1/article/`.
CVE-2026-63670 Cross-Site Scripting (XSS) in CVE-2026-63670 (CVE-2026-63670)
cross-site scripting in CVE-2026-63670 (CVE-2026-63670). Risk of unauthorized operations or information disclosure.
CVE-2026-63669 Vulnerability in CVE-2026-63669 (CVE-2026-63669)
vulnerability in CVE-2026-63669 (CVE-2026-63669). Data can be tampered with by attackers.
CVE-2026-63667 Path Traversal in CVE-2026-63667 (CVE-2026-63667)
path traversal in CVE-2026-63667 (CVE-2026-63667). Confidential information can be exposed externally.
CVE-2026-75011 Vulnerability in CVE-2026-75011 (CVE-2026-75011)
vulnerability in CVE-2026-75011 (CVE-2026-75011). Risk of unauthorized operations or information disclosure.
CVE-2026-47698 Vulnerability in vm2 (CVE-2026-47698)
vulnerability in vm2 (CVE-2026-47698). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.6` or later.
CVE-2026-47686 Vulnerability in vm2 (CVE-2026-47686)
vulnerability in vm2 (CVE-2026-47686). Successful exploitation can lead to full system takeover. Exploitable via ``process``. Mitigation: upgrade to `3.11.6` or later.
CVE-2026-47683 Vulnerability in vm2 (CVE-2026-47683)
vulnerability in vm2 (CVE-2026-47683). Risk of unauthorized operations or information disclosure. Exploitable via ``bufferAllocLimit``. Mitigation: upgrade to `3.11.6` or later.
CVE-2026-55674 Cross-Site Scripting (XSS) in CVE-2026-55674 (CVE-2026-55674)
cross-site scripting in CVE-2026-55674 (CVE-2026-55674). Confidential information can be exposed externally.
CVE-2026-40345 Vulnerability in deepmerge-ts (CVE-2026-40345)
vulnerability in deepmerge-ts (CVE-2026-40345). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0` or later.
CVE-2026-40126 Cross-Site Scripting (XSS) in CVE-2026-40126 (CVE-2026-40126)
cross-site scripting in CVE-2026-40126 (CVE-2026-40126). Risk of unauthorized operations or information disclosure.
CVE-2026-22072 Vulnerability in CVE-2026-22072 (CVE-2026-22072)
vulnerability in CVE-2026-22072 (CVE-2026-22072). Risk of unauthorized operations or information disclosure.
CVE-2026-19986 Vulnerability in CVE-2026-19986 (CVE-2026-19986)
vulnerability in CVE-2026-19986 (CVE-2026-19986). Risk of unauthorized operations or information disclosure.
CVE-2026-19978 Command Injection in CVE-2026-19978 (CVE-2026-19978)
command injection in CVE-2026-19978 (CVE-2026-19978). Risk of unauthorized operations or information disclosure.
CVE-2026-13712 Cross-Site Scripting (XSS) in wordpress (CVE-2026-13712)
cross-site scripting in wordpress (CVE-2026-13712). Risk of unauthorized operations or information disclosure.
CVE-2026-73052 Cross-Site Scripting (XSS) in CVE-2026-73052 (CVE-2026-73052)
cross-site scripting in CVE-2026-73052 (CVE-2026-73052). Successful exploitation can lead to full system takeover.
CVE-2026-73043 Cross-Site Scripting (XSS) in CVE-2026-73043 (CVE-2026-73043)
cross-site scripting in CVE-2026-73043 (CVE-2026-73043). Successful exploitation can lead to full system takeover.
CVE-2026-73050 Cross-Site Scripting (XSS) in CVE-2026-73050 (CVE-2026-73050)
cross-site scripting in CVE-2026-73050 (CVE-2026-73050). Successful exploitation can lead to full system takeover.
CVE-2026-73041 Cross-Site Scripting (XSS) in CVE-2026-73041 (CVE-2026-73041)
cross-site scripting in CVE-2026-73041 (CVE-2026-73041). Successful exploitation can lead to full system takeover.
CVE-2026-14230 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14230)
cross-site scripting in wordpress (CVE-2026-14230). Risk of unauthorized operations or information disclosure.
CVE-2026-14484 Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
CVE-2026-53472 Cross-Site Scripting (XSS) in CVE-2026-53472 (CVE-2026-53472)
cross-site scripting in CVE-2026-53472 (CVE-2026-53472). Confidential information can be exposed externally. Exploitable via ``AgentStatusUpdate.CredentialUrl``.
CVE-2026-14290 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14290)
cross-site scripting in wordpress (CVE-2026-14290). Successful exploitation can lead to full system takeover.
CVE-2026-73665 Vulnerability in CVE-2026-73665 (CVE-2026-73665)
vulnerability in CVE-2026-73665 (CVE-2026-73665). Risk of unauthorized operations or information disclosure.
CVE-2026-18741 Cross-Site Scripting (XSS) in CVE-2026-18741 (CVE-2026-18741)
cross-site scripting in CVE-2026-18741 (CVE-2026-18741). Risk of unauthorized operations or information disclosure.
CVE-2026-73531 Cross-Site Scripting (XSS) in django (CVE-2026-73531)
cross-site scripting in django (CVE-2026-73531). Risk of unauthorized operations or information disclosure.
CVE-2026-73038 Cross-Site Scripting (XSS) in CVE-2026-73038 (CVE-2026-73038)
cross-site scripting in CVE-2026-73038 (CVE-2026-73038). Risk of unauthorized operations or information disclosure.
CVE-2026-73037 Cross-Site Scripting (XSS) in CVE-2026-73037 (CVE-2026-73037)
cross-site scripting in CVE-2026-73037 (CVE-2026-73037). Risk of unauthorized operations or information disclosure.
CVE-2026-73566 Vulnerability in tar (CVE-2026-73566)
vulnerability in tar (CVE-2026-73566). Risk of unauthorized operations or information disclosure. Exploitable via ``tar``. Mitigation: upgrade to `7.5.21` or later.
CVE-2026-73671 Open Redirect in CVE-2026-73671 (CVE-2026-73671)
vulnerability in CVE-2026-73671 (CVE-2026-73671). Risk of unauthorized operations or information disclosure.
CVE-2026-73572 Cross-Site Scripting (XSS) in synacor (CVE-2026-73572)
cross-site scripting in synacor (CVE-2026-73572). Risk of unauthorized operations or information disclosure.
CVE-2026-19744 Cross-Site Scripting (XSS) in CVE-2026-19744 (CVE-2026-19744)
cross-site scripting in CVE-2026-19744 (CVE-2026-19744). Risk of unauthorized operations or information disclosure.
CVE-2026-19716 Cross-Site Scripting (XSS) in CVE-2026-19716 (CVE-2026-19716)
cross-site scripting in CVE-2026-19716 (CVE-2026-19716). Risk of unauthorized operations or information disclosure.
CVE-2025-62318 Cross-Site Request Forgery (CSRF) in CVE-2025-62318 (CVE-2025-62318)
vulnerability in CVE-2025-62318 (CVE-2025-62318). Risk of unauthorized operations or information disclosure.
CVE-2026-55087 Cross-Site Scripting (XSS) in ep_etherpad-lite (CVE-2026-55087)
cross-site scripting in ep_etherpad-lite (CVE-2026-55087). Risk of unauthorized operations or information disclosure. Exploitable via ``String.prototype.replaceAll``. Mitigation: upgrade to `3.1.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →