57,566 vulnerabilities published in 2026
Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu
A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allow
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability
html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scrip
client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Vers
NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown conte
The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']
The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficientl
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when cli
AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote atta
Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious sig
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbit
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is require
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not nec
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not neces
MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the d
A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1
Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been foun
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0
lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is
Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to
RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allow
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all
The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all
The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in a
The Geo Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL path in all versions up to,
The Address Bar Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL Path in all version
The StyleBidet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject ma
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject ma
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject ma
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject ma
Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endp
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unau
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows atta
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unau
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unau
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started