Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-1276
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed…
Qradar Security Information And Event Manager
Mitigation only
MEDIUM 5.4
CVE-2026-32703
OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories modul…
Openproject
16.6.9 / 17.0.6+
MEDIUM 6.1
CVE-2026-32722
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML …
Memray
1.19.2+
HIGH 7.6
CVE-2026-32728
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attack…
Parse Server
8.6.41 / 9.6.0+
CRITICAL 9.8
CVE-2026-29859
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.
Aapanel
Mitigation only
MEDIUM 5.4
CVE-2026-30048
A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized b…
Mitigation only
MEDIUM 6.1
CVE-2026-30695
A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, …
Mitigation only
HIGH 7.2
CVE-2026-3090
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable …
Mitigation only
MEDIUM 6.4
CVE-2026-2512
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2…
Mitigation only
MEDIUM 6.1
CVE-2026-3278
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Si…
Zenworks Service Desk
Mitigation only
MEDIUM 5.3
CVE-2025-12518
beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary…
Mitigation only
HIGH 7.1
CVE-2026-22322
A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create…
Mitigation only
MEDIUM 5.9
CVE-2025-15363
The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-S…
Mitigation only
MEDIUM 6.1
CVE-2026-3512
The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and in…
Mitigation only
MEDIUM 6.1
CVE-2026-31938
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows att…
Jspdf
4.2.1+
MEDIUM 6.1
CVE-2026-1780
The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including,…
Mitigation only
MEDIUM 6.4
CVE-2026-4268
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in al…
Mitigation only
MEDIUM 6.1
CVE-2026-28499
LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a c…
Leafkit
1.14.2+
MEDIUM 5.4
CVE-2026-32840
Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows…
Gs 5008pl Firmware
after 1.00.54
MEDIUM 6.1
CVE-2025-62320
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Becau…
Unica
12.1.11 / 25.1.1.0.1+
MEDIUM 6.1
CVE-2026-30882
Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in t…
Chamilo Lms
1.11.36+
MEDIUM 5.4
CVE-2026-29510
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to injec…
Eth Imc408m Firmware
after 1.0.15
MEDIUM 5.4
CVE-2026-29513
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to injec…
Eth Imc408m Firmware
after 1.0.15
MEDIUM 6.1
CVE-2026-29520
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function th…
Eth Imc408m Firmware
after 1.0.15
MEDIUM 5.4
CVE-2025-65734
An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows at…
Openeclass
3.13+
MEDIUM 6.1
CVE-2025-57543
Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be render…
Netbox
No fix yet
HIGH 7.1
CVE-2026-25369
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflect…
Mitigation only
MEDIUM 6.1
CVE-2025-2274
Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web …
Web Security
after 8.5.6
MEDIUM 5.4
CVE-2026-3024
Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/mod…
Wakyma
Mitigation only
MEDIUM 5.4
CVE-2026-32774
Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts.…
Vulnogram
Patch available