57,566 vulnerabilities published in 2026
Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to e
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electroni
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar
Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar
Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbi
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who con
Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar
Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed
The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place'
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun
Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back
Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to
showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr
showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin
Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Improper validation leads to a generic XSS vector in the language override feature.
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat
An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig
AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vuln
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started