Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2026-30564
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…
Sales And Inventory System
No fix yet
MEDIUM 6.1
CVE-2026-30565
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…
Sales And Inventory System
No fix yet
MEDIUM 6.1
CVE-2026-30566
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…
Sales And Inventory System
No fix yet
MEDIUM 6.4
CVE-2026-2602
The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and inclu…
Mitigation only
MEDIUM 5.4
CVE-2026-2595
The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1…
Mitigation only
HIGH 8.6
CVE-2026-33955
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison vi…
Notesnook Desktop
3.3.11+
CRITICAL 9.6
CVE-2026-33976
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can …
Notesnook Desktop
3.3.11 / 3.3.17+
HIGH 8.2
CVE-2026-33979
Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to preve…
Express Xss Sanitizer
2.0.2+
HIGH 8.2
CVE-2026-33941
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/…
Handlebars
4.7.9+
MEDIUM 6.1
CVE-2026-33883
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could …
Statamic
5.73.16 / 6.7.2+
MEDIUM 5.4
CVE-2026-33045
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20…
Home Assistant
2026.1.0+
MEDIUM 5.4
CVE-2026-33044
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20…
Home Assistant
2026.1.0+
HIGH 8.2
CVE-2026-34375
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes th…
Avideo
after 26.0
MEDIUM 6.1
CVE-2026-30567
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "li…
Inventory System
No fix yet
MEDIUM 6.1
CVE-2026-30569
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…
Inventory System
No fix yet
MEDIUM 6.1
CVE-2026-30570
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_sales.php file via the "limi…
Inventory System
No fix yet
MEDIUM 6.1
CVE-2026-30571
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "l…
Inventory System
No fix yet
MEDIUM 5.4
CVE-2026-30527
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within …
Online Food Ordering System
No fix yet
MEDIUM 5.1
CVE-2026-5010
A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript cod…
Mitigation only
MEDIUM 5.4
CVE-2026-5026
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content.
S…
Langflow
Mitigation only
MEDIUM 6.1
CVE-2026-33758
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authenticatio…
Openbao
2.5.2+
MEDIUM 6.1
CVE-2025-61190
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The …
Dspace
No fix yet
MEDIUM 5.4
CVE-2026-32859
ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to…
Patch available
MEDIUM 5.4
CVE-2026-25100
Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges…
Bludit
3.18.2+
HIGH 7.0
CVE-2026-3457
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows a…
Mitigation only
MEDIUM 5.4
CVE-2026-33559
WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin …
Mitigation only
MEDIUM 5.4
CVE-2026-33673
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS)…
Prestashop
8.2.5 / 9.1.0+
MEDIUM 5.4
CVE-2026-33653
Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2…
Uploady
3.1.2+
MEDIUM 5.4
CVE-2026-33664
Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — des…
Kestra
after 1.3.3
MEDIUM 6.1
CVE-2026-3529
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics GA4 allows Cross-Site S…
Google Analytics Ga4
1.1.14+