Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2026-29100
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML i…
Suitecrm
7.15.1+
CRITICAL 9.0
CVE-2026-32751
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via inner…
Siyuan
3.6.1+
CRITICAL 9.3
CVE-2026-32754
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scr…
Freescout
1.8.209+
MEDIUM 6.1
CVE-2026-32040
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary …
Openclaw
2026.2.23+
HIGH 8.7
CVE-2026-33346
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site script…
Openemr
8.0.0.2+
MEDIUM 5.4
CVE-2026-33299
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my…
Openemr
8.0.0.2+
MEDIUM 5.4
CVE-2026-33303
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to …
Openemr
8.0.0.2+
MEDIUM 6.1
CVE-2026-27570
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConver…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 6.1
CVE-2026-27740
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerabilit…
Discourse
2026.1.2 / 2026.2.1+
MEDIUM 5.4
CVE-2026-32869
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case informat…
Ecase Ecomplaint
10.2.0.0+
MEDIUM 5.4
CVE-2026-32866
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated …
Ecase Ecomplaint
10.2.0.0+
MEDIUM 5.4
CVE-2026-32868
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An a…
Ecase Ecomplaint
10.2.0.0+
MEDIUM 5.1
CVE-2026-32843
Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.ph…
Mitigation only
HIGH 7.1
CVE-2026-27068
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt a…
Mitigation only
HIGH 7.1
CVE-2026-27070
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.T…
Mitigation only
HIGH 7.1
CVE-2026-25438
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks all…
Mitigation only
HIGH 7.1
CVE-2026-25442
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS…
Mitigation only
MEDIUM 6.5
CVE-2025-62043
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue …
Mitigation only
HIGH 7.1
CVE-2025-67618
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.T…
Mitigation only
HIGH 7.1
CVE-2025-68836
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows R…
Mitigation only
MEDIUM 5.4
CVE-2026-21788
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…
Connections
Mitigation only
HIGH 7.1
CVE-2025-50001
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Refle…
Mitigation only
HIGH 7.1
CVE-2025-53222
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription al…
Mitigation only
MEDIUM 5.4
CVE-2024-42210
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known …
Unica
12.1.9+
MEDIUM 6.4
CVE-2026-4120
The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter with…
Mitigation only
MEDIUM 6.4
CVE-2026-4006
The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versio…
Mitigation only
MEDIUM 5.9
CVE-2026-28044
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue…
Mitigation only
HIGH 7.1
CVE-2026-28073
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected …
Mitigation only
HIGH 7.2
CVE-2026-1238
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, …
Mitigation only
MEDIUM 5.4
CVE-2025-15051
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…
Qradar Security Information And Event Manager
Mitigation only