| CVE-2025-69245 | 6.1 | medium | raytha / raytha | Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. | 173d ago |
| CVE-2025-69242 | 6.1 | medium | raytha / raytha | Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. | 173d ago |
| CVE-2017-20219 | 6.1 | medium | — | Serviio PRO 1.8 DLNA Media Streaming Server contains a DOM-based cross-site scripting vulnerability that allows at | 173d ago |
| CVE-2016-20036 | 6.1 | medium | wowza / streaming engine | Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager | 173d ago |
| CVE-2016-20027 | 6.1 | medium | — | ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to | 173d ago |
| CVE-2015-20116 | 6.1 | medium | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject m | 173d ago |
| CVE-2015-20114 | 6.1 | medium | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to exec | 173d ago |
| CVE-2026-22183 | 6.1 | medium | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview function | 176d ago |
| CVE-2025-13702 | 6.1 | medium | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross | 176d ago |
| CVE-2025-12454 | 6.1 | medium | opentext / vertica | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Ve | 176d ago |
| CVE-2025-12453 | 6.1 | medium | opentext / vertica | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Ve | 176d ago |
| CVE-2026-31860 | 6.1 | medium | unjs / unhead | Unhead is a document head and template manager. | 177d ago |
| CVE-2026-2987 | 6.1 | medium | — | The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in ver | 177d ago |
| CVE-2026-1652 | 6.1 | medium | lenovo / smart connect | A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that | 178d ago |
| CVE-2026-31868 | 6.1 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2026-31859 | 6.1 | medium | craftcms / craft cms | Craft is a content management system (CMS). | 178d ago |
| CVE-2026-20117 | 6.1 | medium | cisco / unified contact center express | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could | 178d ago |
| CVE-2026-20116 | 6.1 | medium | — | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterp | 178d ago |
| CVE-2026-32037 | 6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHo | 170d ago |
| CVE-2026-31997 | 6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run | 171d ago |
| CVE-2026-60137exploited | 5.9 | medium | wordpress / wordpress | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__no | 50d ago |
| CVE-2026-29772 | 5.9 | medium | astro / \@astrojs\/node | Astro is a web framework. | 165d ago |
| CVE-2026-4603 | 5.9 | medium | kjur / jsrsasign | Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL | 167d ago |
| CVE-2026-33319 | 5.9 | medium | wwbn / avideo | WWBN AVideo is an open source video platform. | 167d ago |
| CVE-2026-32045 | 5.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway r | 169d ago |
| CVE-2026-33424 | 5.9 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-33129 | 5.9 | medium | h3 / h3 | H3 is a minimal H(TTP) framework. | 169d ago |
| CVE-2024-31119 | 5.9 | medium | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Tria | 169d ago |
| CVE-2026-32935 | 5.9 | medium | phpseclib / phpseclib | phpseclib is a PHP secure communications library. | 170d ago |
| CVE-2026-22737 | 5.9 | medium | vmware / spring framework | Use of Java scripting engine enabled (e.g. | 170d ago |
| CVE-2026-29106 | 5.9 | medium | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-32039 | 5.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group poli | 170d ago |
| CVE-2026-32035 | 5.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts | 170d ago |
| CVE-2026-3579 | 5.9 | medium | wolfssl / wolfssl | wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication | 170d ago |
| CVE-2026-28044 | 5.9 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP | 171d ago |
| CVE-2026-32770 | 5.9 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 171d ago |
| CVE-2026-32632 | 5.9 | medium | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 171d ago |
| CVE-2025-15363 | 5.9 | medium | — | The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low | 171d ago |
| CVE-2026-32462 | 5.9 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin | 176d ago |
| CVE-2026-32419 | 5.9 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Bri | 176d ago |
| CVE-2026-32360 | 5.9 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins | 176d ago |
| CVE-2026-32351 | 5.9 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry Powe | 176d ago |
| CVE-2026-2581 | 5.9 | medium | nodejs / undici | This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). | 177d ago |
| CVE-2026-32235 | 5.9 | medium | linuxfoundation / backstage | Backstage is an open framework for building developer portals. | 177d ago |
| CVE-2026-31875 | 5.9 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2026-7473exploited | 5.8 | medium | arista / eos | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensib | 92d ago |
| CVE-2026-33144 | 5.8 | medium | gpac / gpac | GPAC is an open-source multimedia framework. | 169d ago |
| CVE-2026-33081 | 5.8 | medium | pinchtab / pinchtab | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. | 169d ago |
| CVE-2026-33061 | 5.8 | medium | jexactyl / jexactyl | Jexactyl is a customisable game management panel and billing system. | 169d ago |
| CVE-2026-4366 | 5.8 | medium | redhat / build of keycloak | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP red | 172d ago |
| CVE-2026-2454 | 5.8 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported arr | 173d ago |
| CVE-2025-52644 | 5.8 | medium | hcltech / aion | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. | 173d ago |
| CVE-2026-3099 | 5.8 | medium | gnome / libsoup | A flaw was found in Libsoup. | 177d ago |
| CVE-2026-33473 | 5.7 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-32816 | 5.7 | medium | admidio / admidio | Admidio is an open-source user management solution. | 170d ago |
| CVE-2026-32755 | 5.7 | medium | admidio / admidio | Admidio is an open-source user management solution. | 170d ago |
| CVE-2026-32009 | 5.7 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation th | 170d ago |
| CVE-2026-26933 | 5.7 | medium | elasticsearch / packetbeat | Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial | 170d ago |
| CVE-2026-26931 | 5.7 | medium | elastic / metricbeat | Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat ca | 170d ago |
| CVE-2025-14806 | 5.7 | medium | ibm / planning analytics local | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into stor | 172d ago |