Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2026-49458
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accept…
Dompurify
3.4.6+
MEDIUM 6.1
CVE-2026-49459
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could …
Dompurify
3.4.6+
HIGH 8.5
CVE-2026-48320EPSS 5%
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scri…
Coldfusion
Mitigation only
MEDIUM 6.1
CVE-2026-48761
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAtt…
Symfony
6.4.41 / 7.4.13+
MEDIUM 5.4
CVE-2026-48371
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
Commerce
1.21.0+
MEDIUM 5.4
CVE-2026-48355
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48262
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48263
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48253
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48254
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48255
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48257
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48260
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
MEDIUM 5.4
CVE-2026-48261
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating th…
Experience Manager
after 2020.5.0
HIGH 8.7
CVE-2026-47994
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
Commerce
1.21.0+
HIGH 8.1
CVE-2026-47995
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject maliciou…
Commerce
1.21.0+
HIGH 8.2
CVE-2026-47423
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing br…
Dompurify
Patch available
CRITICAL 9.6
CVE-2026-47428
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCa…
Patch available
MEDIUM 6.1
CVE-2026-45753
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, …
Symfony
6.4.40 / 7.4.12+
MEDIUM 5.4
CVE-2026-45072
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the d…
Symfony
6.4.40 / 7.4.12+
MEDIUM 6.1
CVE-2026-57101
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …
Visual Studio Code
1.128.1+
MEDIUM 5.4
CVE-2026-55135
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.4
CVE-2026-55126
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
HIGH 8.7
CVE-2026-55034
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.4
CVE-2026-55030
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.4
CVE-2026-55016
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.4
CVE-2026-55019
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.4
CVE-2026-55020
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
HIGH 8.7
CVE-2026-55021
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
MEDIUM 5.4
CVE-2026-58647
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing ov…
Power Bi Report Server
15.0.1121.120+