57,566 vulnerabilities published in 2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.
An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the
cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_valid
OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handl
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path
pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffi
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected
WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allo
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote,
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an inpu
hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. Wh
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializ
justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability
justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling.
justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler
justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code s
justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the seriali
NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers
Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without esca
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin al
Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration templa
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows rem
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S
UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This is
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval d
The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization.
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folde
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue ap
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a con
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validat
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syW
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connecti
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatic
darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then rende
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advan
Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site na
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software I
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started