| CVE-2025-52204 | 6.1 | — | — | — | — | A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCus | 199d ago |
| CVE-2026-33499 | 6.1 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 199d ago |
| CVE-2024-51226 | 6.1 | — | — | — | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle | 199d ago |
| CVE-2026-4647 | 6.1 | — | — | — | gnu / binutils | A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object | 199d ago |
| CVE-2026-3635 | 6.1 | — | — | — | fastify / fastify | Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0 | 199d ago |
| CVE-2026-33296 | 6.1 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 200d ago |
| CVE-2026-4069 | 6.1 | — | — | — | — | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter | 202d ago |
| CVE-2026-2723 | 6.1 | — | — | — | — | The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu | 202d ago |
| CVE-2026-2427 | 6.1 | — | — | — | — | The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' | 202d ago |
| CVE-2026-2277 | 6.1 | — | — | — | — | The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' param | 202d ago |
| CVE-2026-1647 | 6.1 | — | — | — | — | The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF | 202d ago |
| CVE-2025-13910 | 6.1 | — | — | — | — | The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_aut | 202d ago |
| CVE-2026-3572 | 6.1 | — | — | — | — | The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scrip | 202d ago |
| CVE-2026-33230 | 6.1 | — | — | — | nltk / nltk | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese | 202d ago |
| CVE-2026-33209 | 6.1 | — | — | — | avohq / avo | Avo is a framework to create admin panels for Ruby on Rails apps. | 202d ago |
| CVE-2026-33140 | 6.1 | — | — | — | parzivalhack / pyspector | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflow | 202d ago |
| CVE-2026-32844 | 6.1 | — | — | — | xinliangcoder / php api doc | XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_m | 202d ago |
| CVE-2026-29828 | 6.1 | — | — | — | dootask / dootask | DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input fiel | 202d ago |
| CVE-2026-32986 | 6.1 | — | — | — | textpattern / textpattern | Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to | 202d ago |
| CVE-2026-33370 | 6.1 | — | — | — | synacor / zimbra collaboration suite | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. | 202d ago |
| CVE-2026-33368 | 6.1 | — | — | — | synacor / zimbra collaboration suite | Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in th | 202d ago |
| CVE-2026-31382 | 6.1 | — | — | — | gainsight / assist | The error_description parameter is vulnerable to Reflected XSS. | 202d ago |
| CVE-2026-33035 | 6.1 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 202d ago |
| CVE-2026-27740 | 6.1 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 203d ago |
| CVE-2026-27570 | 6.1 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 203d ago |
| CVE-2026-31990 | 6.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to | 204d ago |
| CVE-2026-22176 | 6.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script ge | 204d ago |
| CVE-2026-30695 | 6.1 | — | — | — | — | A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess acce | 204d ago |
| CVE-2026-3278 | 6.1 | — | — | — | opentext / zenworks service desk | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZEN | 204d ago |
| CVE-2026-3512 | 6.1 | — | — | — | — | The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET para | 204d ago |
| CVE-2026-1780 | 6.1 | — | — | — | — | The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in | 205d ago |
| CVE-2026-28499 | 6.1 | — | — | — | vapor / leafkit | LeafKit is a templating language with Swift-inspired syntax. | 205d ago |
| CVE-2026-27545 | 6.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows | 205d ago |
| CVE-2026-27523 | 6.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass | 205d ago |
| CVE-2026-22217 | 6.1 | — | — | — | openclaw / openclaw | OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that | 205d ago |
| CVE-2026-22177 | 6.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config en | 205d ago |
| CVE-2026-22882 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2026-20726 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-66633 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-66617 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-66503 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-66042 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-66000 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-65119 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-64776 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-64735 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-64733 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-62500 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-62403 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-61979 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-61952 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-58427 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2025-47873 | 6.1 | — | — | — | canva / affinity | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. | 205d ago |
| CVE-2026-30882 | 6.1 | — | — | — | chamilo / chamilo lms | Chamilo LMS is a learning management system. | 206d ago |
| CVE-2026-29520 | 6.1 | — | — | — | hereta / eth-imc408m firmware | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the | 206d ago |
| CVE-2025-57543 | 6.1 | — | — | — | netbox / netbox | Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. | 206d ago |
| CVE-2025-2274 | 6.1 | — | — | — | forcepoint / web security | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows | 206d ago |
| CVE-2026-4179 | 6.1 | — | — | — | zephyrproject / zephyr | Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop. | 206d ago |
| CVE-2026-3442 | 6.1 | — | — | — | gnu / binutils | A flaw was found in GNU Binutils. | 206d ago |
| CVE-2026-3441 | 6.1 | — | — | — | gnu / binutils | A flaw was found in GNU Binutils. | 206d ago |