Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-73084
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied c…
No fix yet
HIGH 8.8
CVE-2026-71386
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attack…
No fix yet
HIGH 8.7
CVE-2026-70355
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
CRITICAL 9.3
CVE-2026-70306
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20434+
HIGH 7.6
CVE-2026-65767
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to …
Teams
1.0.76.202611302+
MEDIUM 5.4
CVE-2026-64922
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
MEDIUM 5.4
CVE-2026-64916
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
MEDIUM 5.4
CVE-2026-64902
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
MEDIUM 5.4
CVE-2026-64897
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
MEDIUM 5.4
CVE-2026-64900
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
MEDIUM 5.4
CVE-2026-62914
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to pe…
Exchange Server
15.02.2562.046+
MEDIUM 5.4
CVE-2026-62829
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
CRITICAL 9.6
CVE-2026-57104
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele…
Azure Storage Explorer
No fix yet
MEDIUM 5.4
CVE-2026-57105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
MEDIUM 5.4
CVE-2026-21269
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into v…
Coldfusion
No fix yet
MEDIUM 5.3
CVE-2026-18247
A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentiall…
No fix yet
MEDIUM 6.1
CVE-2026-72925
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson…
No fix yet
MEDIUM 5.1
CVE-2026-19434
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the app…
No fix yet
HIGH 7.2
CVE-2026-72747
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in…
No fix yet
MEDIUM 5.4
CVE-2026-72559
A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes …
No fix yet
MEDIUM 5.4
CVE-2026-72553
A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile…
No fix yet
MEDIUM 5.1
CVE-2026-73161
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function…
No fix yet
MEDIUM 5.1
CVE-2026-73158
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are…
No fix yet
MEDIUM 5.1
CVE-2026-73159
Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() …
No fix yet
MEDIUM 5.3
CVE-2026-73156
Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice name…
No fix yet
MEDIUM 6.4
CVE-2026-16974
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S…
No fix yet
MEDIUM 6.3
CVE-2026-66779
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link…
No fix yet
MEDIUM 6.1
CVE-2026-66771
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user …
No fix yet
MEDIUM 5.4
CVE-2026-72743
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders T…
No fix yet
MEDIUM 6.1
CVE-2026-69116
FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicio…
No fix yet