Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-4364
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…
Security Verify Access
after 11.0.2.0
CRITICAL 9.0
CVE-2026-34529
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…
Filebrowser
2.62.2+
MEDIUM 6.9
CVE-2026-34530
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…
Filebrowser
2.62.2+
HIGH 8.7
CVE-2026-34748
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS…
Payload
3.78.0+
MEDIUM 6.1
CVE-2026-33978
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share …
Notesnook Mobile
3.3.17+
MEDIUM 6.1
CVE-2026-20085
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack …
Mitigation only
MEDIUM 6.1
CVE-2026-30526
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login p…
Zoo Management System
No fix yet
MEDIUM 5.4
CVE-2026-29598
Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers …
Mitigation only
MEDIUM 6.4
CVE-2025-13535
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in al…
Mitigation only
MEDIUM 6.1
CVE-2026-3877
A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a ma…
Fm
10.13.403+
MEDIUM 5.4
CVE-2026-21631
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Joomla\!
5.4.4 / 6.0.4+
MEDIUM 5.4
CVE-2026-21632
Lack of output escaping for article titles leads to XSS vectors in various locations.
Joomla\!
5.4.4 / 6.0.4+
MEDIUM 6.5
CVE-2026-34889
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery P…
Mitigation only
MEDIUM 6.1
CVE-2026-5255
A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component …
Simple Laundry System
No fix yet
MEDIUM 5.4
CVE-2026-35054
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts throug…
Xenforo
2.3.9+
MEDIUM 6.1
CVE-2026-35055
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicio…
Xenforo
2.2.18 / 2.3.9+
MEDIUM 5.4
CVE-2026-35057
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy pr…
Xenforo
2.2.19 / 2.3.10+
MEDIUM 6.4
CVE-2026-2480
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the…
Mitigation only
HIGH 8.2
CVE-2026-34585
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side…
Siyuan
3.6.2+
MEDIUM 6.1
CVE-2026-34605
SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to…
Siyuan
3.6.2+
CRITICAL 9.0
CVE-2026-34448
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field …
Siyuan
3.6.2+
MEDIUM 6.1
CVE-2026-34405
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old…
Og Image
6.2.5+
MEDIUM 6.1
CVE-2026-34739
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request paramete…
Avideo
after 26.0
MEDIUM 6.4
CVE-2026-34716
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifica…
Avideo
after 26.0
MEDIUM 6.1
CVE-2026-34396
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms wi…
Avideo
after 26.0
MEDIUM 6.1
CVE-2026-34206
Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet.…
Captcha Protect
1.12.2+
MEDIUM 5.4
CVE-2026-32607
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…
Discourse
2026.1.3 / 2026.2.2+
MEDIUM 5.4
CVE-2026-32243
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…
Discourse
2026.1.3 / 2026.2.2+
MEDIUM 5.4
CVE-2026-32273
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…
Discourse
2026.1.3 / 2026.2.2+
MEDIUM 6.1
CVE-2026-34231
Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} templat…
Slippers
after 0.6.2