CVE Database

57+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS

57 results for "CWE-79"

CVE-2025-55064
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Dec 29, 2025
CVE-2025-55063
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Dec 29, 2025
CVE-2025-55062
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Dec 29, 2025
CVE-2025-68387
6.1 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be …

Dec 18, 2025
CVE-2025-68385
7.2 HIGH

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be …

Dec 18, 2025
CVE-2025-37732
5.4 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the …

Dec 15, 2025
CVE-2025-54353
5.4 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox …

Dec 9, 2025
CVE-2025-64030
5.4 MEDIUM

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter …

Dec 1, 2025
CVE-2025-55059
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-55056
4.8 MEDIUM

Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-58324
6.4 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, …

Oct 14, 2025
CVE-2025-31366
4.7 MEDIUM

An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all …

Oct 14, 2025
CVE-2025-7746

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially …

Sep 9, 2025
CVE-2025-55054
6.1 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Sep 9, 2025
CVE-2025-55047
8.4 HIGH

CWE-798 Use of Hard-coded Credentials

Sep 9, 2025
CVE-2025-52037
6.1 MEDIUM

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of …

Aug 26, 2025
CVE-2025-52036
6.1 MEDIUM

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of …

Aug 26, 2025
CVE-2025-32932
6.5 MEDIUM

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all …

Aug 12, 2025
CVE-2025-36605
6.1 MEDIUM

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of …

Aug 4, 2025
CVE-2025-46383
6.1 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Jul 20, 2025
CVE-2025-5742
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated user modifies configuration parameters on the web server

Jun 10, 2025
CVE-2025-3905
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting PLC system variables that could cause an unvalidated data injected by …

Jun 10, 2025
CVE-2025-3899
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Certificates page on Webserver that could cause an unvalidated data injected …

Jun 10, 2025
CVE-2025-3117
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting configuration file paths that could cause an unvalidated data injected by …

Jun 10, 2025
CVE-2025-23179
5.5 MEDIUM

CWE-798: Use of Hard-coded Credentials

Apr 29, 2025
CVE-2025-23175
6.1 MEDIUM

Multiple XSS (CWE-79)

Apr 22, 2025
CVE-2025-24909
4.4 MEDIUM

Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that …

Apr 16, 2025
CVE-2025-0757
4.4 MEDIUM

Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that …

Apr 16, 2025
CVE-2025-22855
2.7 LOW

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send …

Apr 8, 2025
CVE-2019-16151
4.7 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker …

Mar 21, 2025
CVE-2024-26006
7.5 HIGH

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below …

Mar 14, 2025
CVE-2023-37933
8.8 HIGH

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows …

Mar 11, 2025
CVE-2024-37360
4.4 MEDIUM

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize …

Feb 19, 2025
CVE-2024-27780
2.2 LOW

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident …

Feb 11, 2025
CVE-2024-8401
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the …

Jan 28, 2025
CVE-2024-48893
6.8 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to …

Jan 14, 2025
CVE-2024-47925
7.5 HIGH

Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47924
7.5 HIGH

Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47920
7.5 HIGH

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47917
7.5 HIGH

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-50377
6.5 MEDIUM

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). …

Nov 26, 2024
CVE-2024-50376
7.3 HIGH

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD …

Nov 26, 2024
CVE-2024-45254
7.5 HIGH

VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nov 14, 2024
CVE-2024-23906
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration …

Sep 11, 2024
CVE-2024-42335
5.4 MEDIUM

7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Aug 20, 2024
CVE-2024-31199
8.8 HIGH

A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

Jul 31, 2024
CVE-2024-38430
5.4 MEDIUM

Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jul 30, 2024
CVE-2024-38436
6.1 MEDIUM

Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jul 21, 2024
CVE-2024-6528
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where …

Jul 11, 2024
CVE-2024-36397
6.1 MEDIUM

Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.