Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-60636
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
Mitigation only
HIGH 8.8
CVE-2026-60637
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60638
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60639
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60633
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
MEDIUM 6.1
CVE-2026-52475
Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file
No fix yet
HIGH 8.7
CVE-2026-47685
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenti…
Fogproject
1.5.10.1832+
HIGH 8.7
CVE-2026-47687
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectFor…
Fogproject
1.5.10.1832+
MEDIUM 5.2
CVE-2026-47689
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow(…
Fogproject
1.5.10.1832+
HIGH 8.1
CVE-2026-50758
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter
Mitigation only
HIGH 7.3
CVE-2026-55081
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflect…
Patch available
MEDIUM 6.2
CVE-2026-28315
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclos…
Serv U
2026.3+
CRITICAL 9.3
CVE-2026-65048
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatab…
No fix yet
MEDIUM 5.4
CVE-2026-64628
Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads con…
No fix yet
MEDIUM 6.4
CVE-2026-15145
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fanc…
Patch available
HIGH 8.8
CVE-2026-11767
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputti…
Mitigation only
MEDIUM 6.4
CVE-2026-15156
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Read…
No fix yet
MEDIUM 6.1
CVE-2023-37508
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain brows…
Devops Plan
3.0.5+
MEDIUM 6.1
CVE-2026-51025
Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageCo…
No fix yet
MEDIUM 6.4
CVE-2026-12900
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/i…
No fix yet
MEDIUM 5.4
CVE-2026-44229
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a…
Request Tracker
5.0.10 / 6.0.3+
MEDIUM 6.1
CVE-2026-44230
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not in…
Request Tracker
5.0.10 / 6.0.3+
HIGH 8.6
CVE-2026-60028
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable …
No fix yet
MEDIUM 5.1
CVE-2026-60029
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable …
No fix yet
CRITICAL 9.4
CVE-2026-60034
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS …
No fix yet
MEDIUM 6.1
CVE-2026-44227
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scri…
Request Tracker
6.0.3+
MEDIUM 5.4
CVE-2026-44228
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Script…
Request Tracker
6.0.3+
CRITICAL 9.3
CVE-2026-39878
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti…
Mitigation only
MEDIUM 6.1
CVE-2026-26483
Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The applicat…
No fix yet
MEDIUM 5.4
CVE-2026-6793
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT …
No fix yet