Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2026-6565
The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scr…
Mitigation only
MEDIUM 6.1
CVE-2026-44903
Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy we…
Prometheus
3.5.3 / 3.11.3+
MEDIUM 6.1
CVE-2026-44896
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() functio…
Mistune
after 3.2.0
MEDIUM 6.1
CVE-2026-44897
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concaten…
Mistune
3.2.1+
MEDIUM 6.1
CVE-2026-44898
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (…
Mistune
3.2.1+
MEDIUM 6.1
CVE-2026-44899
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options…
Mistune
3.2.1+
MEDIUM 6.1
CVE-2026-44708
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($…
Mistune
3.2.1+
MEDIUM 5.4
CVE-2026-44831
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, r…
Snipe It
8.4.1+
MEDIUM 5.2
CVE-2025-68709
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivit…
Mitigation only
HIGH 8.7
CVE-2026-44667
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via…
Mitigation only
HIGH 8.7
CVE-2026-44669
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via…
Mitigation only
MEDIUM 6.1
CVE-2026-48903
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-48905
Lack of input filtering leads to an XSS vector in the HTML filter code.
Joomla\!
5.4.6 / 6.1.0+
HIGH 8.7
CVE-2026-44729
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded fi…
Twenty
after 1.18.0
MEDIUM 6.1
CVE-2026-30895
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-25900
Lack of output escaping leads to a XSS vector in the feed modules.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-25901
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-30894
Lack of output escaping leads to a XSS vector in the content history component.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2025-36148
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerabl…
Financial Transaction Manager For Multiplatform
3.2.4.16+
HIGH 7.6
CVE-2025-36126
IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) …
Cognos Analytics
12.1.2+
MEDIUM 6.5
CVE-2026-27427
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS.
This …
Mitigation only
MEDIUM 6.5
CVE-2026-45435
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS.…
Mitigation only
MEDIUM 6.5
CVE-2025-62745
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.
T…
Mitigation only
HIGH 7.2
CVE-2026-48848
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injecti…
Patch available
MEDIUM 6.1
CVE-2026-45249
A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic.
This issue affects Apache EChart…
Echarts
6.1.0+
MEDIUM 6.1
CVE-2018-25349
userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP hea…
No fix yet
HIGH 8.7
CVE-2026-41147
NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insu…
Patch available
HIGH 7.2
CVE-2026-40596
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML b…
Patch available
HIGH 7.6
CVE-2026-40597
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerabilit…
Patch available
MEDIUM 6.9
CVE-2026-40598
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved fro…
Patch available