Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-33411
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a potential stored XSS in topic tit…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.1
CVE-2026-33230
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…
Nltk
after 3.9.3
MEDIUM 6.1
CVE-2026-33209
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site scripting (XSS) vulnerability exist…
Avo
3.30.3+
HIGH 8.7
CVE-2026-33172
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…
Statamic
5.73.14 / 6.7.0+
MEDIUM 6.1
CVE-2026-33140
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and pri…
Pyspector
0.1.7+
MEDIUM 5.4
CVE-2025-63260
SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.
Syncfusion
No fix yet
MEDIUM 6.1
CVE-2026-32844
XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.php that allows remote attack…
Php Api Doc
after 2019-03-24
MEDIUM 6.5
CVE-2026-30578
File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of the GET request to invoke arbit…
File Thingie
Mitigation only
MEDIUM 6.5
CVE-2026-30579
File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a…
File Thingie
Mitigation only
MEDIUM 6.1
CVE-2026-29828
DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc.
Dootask
after 1.6.27
MEDIUM 6.1
CVE-2026-32986
Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploit…
Textpattern
No fix yet
MEDIUM 6.1
CVE-2026-33370
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase…
Zimbra Collaboration Suite
10.1.16+
MEDIUM 6.1
CVE-2026-33368
Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/…
Zimbra Collaboration Suite
10.1.16+
MEDIUM 6.1
CVE-2026-31382
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.
Assist
No fix yet
MEDIUM 6.1
CVE-2026-33135
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_me…
Wegia
3.6.7+
MEDIUM 6.1
CVE-2026-33136
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_…
Wegia
3.6.7+
MEDIUM 5.9
CVE-2024-31119
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyllou Special Box for Content a…
Mitigation only
MEDIUM 5.4
CVE-2026-33080
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two …
Filament
4.8.5 / 5.3.5+
CRITICAL 9.0
CVE-2026-33066
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetS…
Siyuan
3.6.1+
CRITICAL 9.0
CVE-2026-33067
SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template l…
Siyuan
3.6.1+
MEDIUM 5.4
CVE-2026-33061
Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80ef…
Jexactyl
after 3.8.0
MEDIUM 6.1
CVE-2026-4474
A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php.…
University Management System
No fix yet
MEDIUM 5.4
CVE-2026-33051
Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor render…
Craft Cms
5.9.11+
MEDIUM 6.1
CVE-2026-33035
WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attacker…
Avideo
26.0+
MEDIUM 6.1
CVE-2026-32940
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and…
Siyuan
3.6.1+
CRITICAL 9.6
CVE-2026-32890
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and…
Anchorr
after 1.4.1
MEDIUM 6.4
CVE-2026-32880
ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaSc…
Churchcrm
7.0.2+
MEDIUM 5.4
CVE-2026-32757
Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value inst…
Admidio
5.0.7+
MEDIUM 5.4
CVE-2026-33395
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discourse-graphviz plugin contains …
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.1
CVE-2026-29106
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the val…
Suitecrm
7.15.1 / 8.9.3+