57,566 vulnerabilities published in 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redire
A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 a
Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerab
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wr
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file ca
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page.
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and
PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe j
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Secu
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbi
marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti
LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are
The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is
setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo
AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering d
Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations th
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp
A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started