Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2026-7475
The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to,…
Mitigation only
MEDIUM 6.4
CVE-2026-7650
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-down…
Mitigation only
MEDIUM 6.4
CVE-2026-5341
The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all ve…
Mitigation only
HIGH 7.2
CVE-2026-7330
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to ins…
Mitigation only
MEDIUM 5.4
CVE-2024-33724
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
Mitigation only
MEDIUM 6.1
CVE-2023-42343
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
Mitigation only
MEDIUM 6.1
CVE-2023-42345
A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
Mitigation only
MEDIUM 6.1
CVE-2022-23961
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthen…
Mitigation only
MEDIUM 6.1
CVE-2026-8106
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential the…
Enterprise Server
3.19.6 / 3.20.2+
MEDIUM 6.1
CVE-2026-41929
Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attac…
Patch available
MEDIUM 6.1
CVE-2026-32207
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…
Azure Machine Learning
Mitigation only
MEDIUM 6.1
CVE-2026-39823
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were t…
Go
1.25.10 / 1.26.3+
MEDIUM 6.1
CVE-2026-44742
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2…
Postorius
after 1.3.13
HIGH 7.6
CVE-2026-41904
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission c…
Mitigation only
HIGH 7.0
CVE-2026-41653
BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. …
Mitigation only
MEDIUM 5.4
CVE-2026-36388
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This f…
Mitigation only
MEDIUM 5.4
CVE-2026-36341
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment fie…
Patch available
MEDIUM 6.1
CVE-2025-67202
Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL be…
Mitigation only
HIGH 7.1
CVE-2026-41554
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS.
This issu…
Mitigation only
HIGH 8.8
CVE-2026-5784
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD…
Mitigation only
MEDIUM 5.4
CVE-2026-8080
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS.
This issue…
Misp
2.5.37+
HIGH 8.8
CVE-2026-3953
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Pro…
Mitigation only
MEDIUM 6.5
CVE-2026-27421
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XS…
Mitigation only
MEDIUM 5.9
CVE-2025-62127
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS…
Mitigation only
MEDIUM 6.1
CVE-2026-41661
Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admid…
Mitigation only
CRITICAL 9.1
CVE-2026-41201
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In vers…
Mitigation only
MEDIUM 5.4
CVE-2026-40296
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatt…
Phpspreadsheet
1.30.4 / 2.1.16+
HIGH 8.4
CVE-2026-40171
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @…
Mitigation only
MEDIUM 5.4
CVE-2026-8012
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to i…
Chrome
148.0.7778.96+
MEDIUM 5.4
CVE-2026-7958
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious…
Chrome
148.0.7778.96+