Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.7
CVE-2026-35218
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, querie…
Budibase
3.32.5+
MEDIUM 5.4
CVE-2026-5468
A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument …
Casdoor
Mitigation only
MEDIUM 5.4
CVE-2026-4107
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
Manageengine Exchange Reporter Plus
5.8+
MEDIUM 6.1
CVE-2026-35539
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mod…
Webmail
1.5.14 / 1.6.14+
MEDIUM 6.1
CVE-2026-35508
Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,
Shynet
0.14.0+
MEDIUM 6.1
CVE-2026-30251
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attack…
Zenshare Suite
Mitigation only
MEDIUM 6.1
CVE-2026-30252
Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows atta…
Zencrm
Mitigation only
MEDIUM 6.1
CVE-2026-35466
XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services
Cveclient
1.0.24+
MEDIUM 5.4
CVE-2026-34848
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow to…
Hoppscotch
2026.3.0+
CRITICAL 9.3
CVE-2026-34932
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is…
Hoppscotch
2026.3.0+
HIGH 7.8
CVE-2026-5429
Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat acto…
Mitigation only
HIGH 8.2
CVE-2026-34725
DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-c…
Patch available
MEDIUM 6.1
CVE-2026-34606
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, …
Learning
2.48.0+
MEDIUM 6.1
CVE-2026-34598
YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious att…
Yeswiki
4.6.0+
MEDIUM 5.4
CVE-2026-34821
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An auth…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34822
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authe…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34823
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated …
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34974
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed …
Phpmyfaq
4.1.1+
MEDIUM 5.4
CVE-2026-34816
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An auth…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34817
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authen…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34818
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authen…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34819
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authentic…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34820
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacke…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34812
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenti…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34813
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated a…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34814
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34815
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticat…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34807
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated …
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34808
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticate…
Firewall Community
after 3.3.25
MEDIUM 5.4
CVE-2026-34809
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated at…
Firewall Community
after 3.3.25