Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-54188
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
Mitigation only
HIGH 7.1
CVE-2026-54189
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
Mitigation only
HIGH 7.1
CVE-2026-54192
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
Mitigation only
HIGH 7.1
CVE-2026-54195
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
Mitigation only
HIGH 7.1
CVE-2026-49778
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
Mitigation only
HIGH 7.1
CVE-2026-49074
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
Mitigation only
HIGH 7.1
CVE-2026-48869
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Mitigation only
HIGH 8.2
CVE-2026-48788
Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contai…
Patch available
HIGH 7.1
CVE-2026-42385
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
Mitigation only
MEDIUM 6.1
CVE-2026-44587
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to esc…
Carrierwave
2.2.7 / 3.1.3+
HIGH 7.1
CVE-2026-41557
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
Mitigation only
HIGH 7.1
CVE-2026-40765
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
Mitigation only
HIGH 7.1
CVE-2026-39597
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
Mitigation only
HIGH 7.1
CVE-2026-39548
Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.
Mitigation only
HIGH 7.1
CVE-2026-22339
Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.
Mitigation only
HIGH 7.1
CVE-2026-22328
Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.
Mitigation only
HIGH 7.1
CVE-2026-22329
Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions.
Mitigation only
MEDIUM 6.1
CVE-2026-12459
Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) …
Chrome
149.0.7827.155+
MEDIUM 6.2
CVE-2026-11975
Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute…
Patch available
HIGH 7.1
CVE-2025-69151
Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions.
Mitigation only
HIGH 7.1
CVE-2025-69104
Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.
Mitigation only
HIGH 7.1
CVE-2025-59560
Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.
Mitigation only
HIGH 7.1
CVE-2025-31013
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS.
This issue …
Mitigation only
HIGH 7.1
CVE-2024-49269
Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
Mitigation only
HIGH 7.4
CVE-2026-48294
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attack…
Acrobat
after 26.5.2.2
HIGH 7.5
CVE-2026-46955
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-…
Human Resources
after 12.2.15
CRITICAL 9.6
CVE-2026-46856
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions t…
Enterprise Manager Base Platform
Mitigation only
CRITICAL 9.6
CVE-2026-46853
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions t…
Enterprise Manager Base Platform
Mitigation only
MEDIUM 6.1
CVE-2026-12425
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allow…
Employee Access Center
Mitigation only
MEDIUM 5.4
CVE-2024-30476
PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor coul…
Mitigation only