57,566 vulnerabilities published in 2026
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX
Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The
Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a m
A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attac
YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts throug
Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows atta
Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for exte
Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attacker
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject ma
Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner
The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' paramete
A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically prox
Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.
AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through
html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js cont
ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows re
Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary
An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig
SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.
Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code
A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker
A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user
A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficie
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the
lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization ca
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec
Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, an
Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thr
SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into
Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind ma
SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scri
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the
Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and Sym
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripti
URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th
A reflected cross-site scripting (xss) vulnerability exists in the ldapUser functionality of MedDream PACS Premium 7.3.6
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started