VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2126 CVEsRSS

CVE-2026-45483Medium· 4.6
3mo ago

Microsoft Office Project Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-45479Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-45453Medium· 5.4
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.59%via CVEORG
CVE-2026-47637Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-41098High· 8.4
3mo ago

Azure Stack Edge Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Azure Stack EdgeEPSS 0.83%via CVEORG
CVE-2026-47636Medium· 5.4
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.59%via CVEORG
CVE-2026-47638Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-47639Medium· 5.4
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.59%via CVEORG
CVE-2026-33113Medium· 5.4
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.60%via CVEORG
CVE-2026-45462Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-45465Medium· 5.4
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.59%via CVEORG
CVE-2026-45464Medium· 5.4
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.59%via CVEORG
CVE-2026-45644High· 8.0
3mo ago

Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft Live Share Canvas SDKEPSS 0.81%via CVEORG
CVE-2026-47640Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-45481High· 7.3
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.65%via CVEORG
CVE-2026-48562Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-47933Medium· 4.8
3mo ago

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaSc…

▾ Sunlitadobe · coldfusionEPSS 0.36%via NVD
CVE-2026-34693High· 8.0
3mo ago

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, pot…

▾ Twilightadobe · experience_managerEPSS 0.57%via NVD
CVE-2026-34691Critical· 9.3
3mo ago

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Mali…

▾ Midnightadobe · experience_managerEPSS 0.74%via NVD
CVE-2026-47631High· 8.1
3mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · exchange_serverEPSS 0.47%via NVD
CVE-2026-45501Medium· 6.5
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · exchange_serverEPSS 0.46%via NVD
CVE-2026-45500Medium· 6.1
3mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · exchange_serverEPSS 0.41%via NVD
CVE-2026-41846Medium· 5.9
3mo ago

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulne…

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulne…

▾ Sunlitvmware · spring_frameworkEPSS 0.24%via NVD
CVE-2026-41845High· 7.1
3mo ago

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.…

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.…

▾ Twilightvmware · spring_frameworkEPSS 0.28%via NVD
CVE-2026-34694Medium· 4.8
3mo ago

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable fo…

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable fo…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-33244Medium· 5.4
3mo ago

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

▾ Sunlitreact-router · react-routerEPSS 0.14%via GHSA
CVE-2026-44651None
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code send…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-45668None
4mo ago

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traver…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-42502Medium· 6.1
4mo ago

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-41147High· 8.7
4mo ago

NukeViet CMS is a multi Content Management System

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies pri…

▾ TwilightEPSS 0.61%via NVD
CWE-79 vulnerabilities (CVEs) — page 50 · VulnSea