Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-22520
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework a…
No fix yet
HIGH 7.1
CVE-2026-22523
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin …
Mitigation only
HIGH 7.1
CVE-2026-22524
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows R…
Mitigation only
HIGH 7.1
CVE-2026-22491
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro…
Mitigation only
HIGH 7.1
CVE-2025-69096
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zorka allows Reflected XSS.This i…
Mitigation only
MEDIUM 5.4
CVE-2026-3212
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS)…
Tagify
1.2.49+
MEDIUM 5.4
CVE-2026-3215
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora allows Cross-Site Scripting (X…
Islandora
2.17.5+
MEDIUM 6.1
CVE-2026-3217
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross…
Saml Sso Service Provider
3.1.3+
MEDIUM 5.4
CVE-2026-2348
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (…
Quick Edit
1.0.5+
MEDIUM 6.1
CVE-2026-2349
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons allows Cross-Site Scripting (XS…
Ui Icons
1.0.1+
MEDIUM 5.4
CVE-2026-24750
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper…
Kiteworks
9.2.1+
MEDIUM 5.4
CVE-2026-20108
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cro…
Catalyst Sd Wan Manager
20.12.5.3 / 20.15.4.2+
MEDIUM 5.4
CVE-2026-4816
A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScr…
Support Board
3.7.8+
MEDIUM 6.1
CVE-2025-40842
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a
Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to
unauthori…
Indoor Connect 8855 Firmware
2025.q3+
MEDIUM 6.1
CVE-2026-2072
Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue af…
Infrastructure Analytics Advisor
11.0.5-00+
MEDIUM 6.4
CVE-2026-4766
The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up…
Mitigation only
MEDIUM 6.1
CVE-2026-33347
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerab…
Commonmark
2.8.2+
MEDIUM 5.4
CVE-2026-33331
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.9, a stored cross-site scr…
Orpc
1.13.9+
MEDIUM 5.4
CVE-2026-33400
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in t…
Wallos
4.7.0+
CRITICAL 9.6
CVE-2026-33334
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…
Vikunja
2.2.2+
MEDIUM 5.4
CVE-2026-29840
JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. T…
Jizhicms
after 2.5.6
MEDIUM 6.1
CVE-2026-30661
iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allow…
Icms
No fix yet
MEDIUM 6.1
CVE-2026-4754
CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
Android Imagemagick7
7.1.2-11+
MEDIUM 5.4
CVE-2026-4626
A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The m…
Online Lawyer Management System
No fix yet
MEDIUM 6.1
CVE-2026-33170
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…
Rails
7.2.3.1 / 8.0.4.1+
MEDIUM 6.1
CVE-2026-33167
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions p…
Rails
8.1.2.1+
HIGH 8.7
CVE-2026-32277
Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue…
Connect Cms
1.41.1 / 2.41.1+
MEDIUM 5.4
CVE-2025-60948
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that…
Csweb
Patch available
MEDIUM 6.1
CVE-2026-32851
MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex…
Mailenable
10.55+
MEDIUM 6.1
CVE-2026-32852
MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex…
Mailenable
10.55+