57,566 vulnerabilities published in 2026
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun
Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back
Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to
showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr
showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin
Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Improper validation leads to a generic XSS vector in the language override feature.
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat
An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig
AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vuln
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the S
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containi
Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T
Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit
Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit
The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an
Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E
Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, Global
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'c
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started