| CVE-2026-20994 | 6.1 | — | — | — | samsung / account | URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access tok | 206d ago |
| CVE-2025-69245 | 6.1 | — | — | — | raytha / raytha | Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. | 206d ago |
| CVE-2025-69242 | 6.1 | — | — | — | raytha / raytha | Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. | 206d ago |
| CVE-2017-20219 | 6.1 | — | — | — | — | Serviio PRO 1.8 DLNA Media Streaming Server contains a DOM-based cross-site scripting vulnerability that allows at | 206d ago |
| CVE-2016-20036 | 6.1 | — | — | — | wowza / streaming engine | Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager | 206d ago |
| CVE-2016-20027 | 6.1 | — | — | — | — | ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to | 206d ago |
| CVE-2015-20116 | 6.1 | — | — | — | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject m | 206d ago |
| CVE-2015-20114 | 6.1 | — | — | — | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to exec | 206d ago |
| CVE-2026-22183 | 6.1 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview function | 209d ago |
| CVE-2025-13702 | 6.1 | — | — | — | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross | 209d ago |
| CVE-2025-12454 | 6.1 | — | — | — | opentext / vertica | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Ve | 209d ago |
| CVE-2025-12453 | 6.1 | — | — | — | opentext / vertica | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Ve | 209d ago |
| CVE-2026-31860 | 6.1 | — | — | — | unjs / unhead | Unhead is a document head and template manager. | 210d ago |
| CVE-2026-2987 | 6.1 | — | — | — | — | The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in ver | 210d ago |
| CVE-2026-2514 | 6.1 | — | — | — | progress / flowmon anomaly detection system | In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with acces | 210d ago |
| CVE-2026-2513 | 6.1 | — | — | — | progress / flowmon anomaly detection system | A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who cl | 210d ago |
| CVE-2026-1652 | 6.1 | — | — | — | lenovo / smart connect | A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that | 211d ago |
| CVE-2026-31868 | 6.1 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 211d ago |
| CVE-2026-31859 | 6.1 | — | — | — | craftcms / craft cms | Craft is a content management system (CMS). | 211d ago |
| CVE-2026-20117 | 6.1 | — | — | — | cisco / unified contact center express | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could | 211d ago |
| CVE-2026-20116 | 6.1 | — | — | — | — | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterp | 211d ago |
| CVE-2026-32037 | 6 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHo | 203d ago |
| CVE-2026-31997 | 6 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run | 204d ago |
| CVE-2026-60137zero day | 5.9 | 5.9% | 3/3 | same day | wordpress / wordpress | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__no | 83d ago |
| CVE-2026-29772 | 5.9 | — | — | — | astro / \@astrojs\/node | Astro is a web framework. | 198d ago |
| CVE-2026-4603 | 5.9 | — | — | — | kjur / jsrsasign | Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL | 199d ago |
| CVE-2026-33319 | 5.9 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 200d ago |
| CVE-2026-32045 | 5.9 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway r | 202d ago |
| CVE-2026-33424 | 5.9 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 202d ago |
| CVE-2026-33129 | 5.9 | — | — | — | h3 / h3 | H3 is a minimal H(TTP) framework. | 202d ago |
| CVE-2024-31119 | 5.9 | — | — | — | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Tria | 202d ago |
| CVE-2026-32935 | 5.9 | — | — | — | phpseclib / phpseclib | phpseclib is a PHP secure communications library. | 203d ago |
| CVE-2026-22737 | 5.9 | — | — | — | vmware / spring framework | Use of Java scripting engine enabled (e.g. | 203d ago |
| CVE-2026-29106 | 5.9 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 203d ago |
| CVE-2026-32039 | 5.9 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group poli | 203d ago |
| CVE-2026-32035 | 5.9 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts | 203d ago |
| CVE-2026-3579 | 5.9 | — | — | — | wolfssl / wolfssl | wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication | 203d ago |
| CVE-2026-28044 | 5.9 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP | 203d ago |
| CVE-2026-32770 | 5.9 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 204d ago |
| CVE-2026-32632 | 5.9 | — | — | — | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 204d ago |
| CVE-2025-15363 | 5.9 | — | — | — | — | The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low | 204d ago |
| CVE-2026-32462 | 5.9 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin | 209d ago |
| CVE-2026-32419 | 5.9 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Bri | 209d ago |
| CVE-2026-32360 | 5.9 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins | 209d ago |
| CVE-2026-32351 | 5.9 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry Powe | 209d ago |
| CVE-2026-2581 | 5.9 | — | — | — | nodejs / undici | This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). | 210d ago |
| CVE-2026-32235 | 5.9 | — | — | — | linuxfoundation / backstage | Backstage is an open framework for building developer portals. | 210d ago |
| CVE-2026-31875 | 5.9 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 211d ago |
| CVE-2026-7473zero day | 5.8 | 0.65% | 3/3 | 31d before | arista / eos | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensib | 125d ago |
| CVE-2026-33144 | 5.8 | — | — | — | gpac / gpac | GPAC is an open-source multimedia framework. | 202d ago |
| CVE-2026-33081 | 5.8 | — | — | — | pinchtab / pinchtab | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. | 202d ago |
| CVE-2026-33061 | 5.8 | — | — | — | jexactyl / jexactyl | Jexactyl is a customisable game management panel and billing system. | 202d ago |
| CVE-2026-4366 | 5.8 | — | — | — | redhat / build of keycloak | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP red | 204d ago |
| CVE-2026-2454 | 5.8 | — | — | — | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported arr | 206d ago |
| CVE-2025-52644 | 5.8 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. | 206d ago |
| CVE-2026-3099 | 5.8 | — | — | — | gnome / libsoup | A flaw was found in Libsoup. | 210d ago |
| CVE-2026-33473 | 5.7 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-32816 | 5.7 | — | — | — | admidio / admidio | Admidio is an open-source user management solution. | 203d ago |
| CVE-2026-32755 | 5.7 | — | — | — | admidio / admidio | Admidio is an open-source user management solution. | 203d ago |
| CVE-2026-32009 | 5.7 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation th | 203d ago |