By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 56 of 86
- CVE-2026-46523MEDIUM 6.2
ImageMagick, widely used image processing software, contains a memory safety defect that can be triggered when processing specially crafted MSL (Magick Scripting Language) image files. The vulnerability allows an attacker with local file access to cause the application to crash or potentially execute code by manipulating freed memory. This affects both the maintained 7.x branch and the legacy 6.x branch before specific patch versions.
- CVE-2026-46557MEDIUM 6.2
ImageMagick, a widely-used image editing and manipulation library, contains a stack overflow vulnerability in its fx (effects) operation. When processing specially crafted input, the affected code fails to validate recursion depth, allowing an attacker to exhaust the stack and crash the application or potentially execute arbitrary code. The vulnerability affects all versions before 7.1.2-23 and can be triggered locally without user interaction or special privileges.
- CVE-2026-47902MEDIUM 6.2
CAI Content Credentials, Adobe's implementation of Content Provenance and Authentication, contains a flaw that allows attackers to consume excessive system resources without any user action required. This can crash or severely degrade applications using affected versions of the c2pa-web library (0.7.1 and earlier) or the c2pa core library (v0.80.1 and earlier). The vulnerability is a resource exhaustion issue—an attacker sends specially crafted input that forces the application to allocate memory or processing power until the system becomes unresponsive.
- CVE-2026-47903MEDIUM 6.2
CAI Content Credentials, Adobe's implementation for managing content provenance and authenticity, contains a flaw in how it validates input data. Versions [email protected], c2pa-v0.80.1 and earlier can be crashed by sending specially crafted input, causing a denial-of-service condition. No user interaction is required—an attacker can trigger the crash remotely, making this a network-reachable availability risk.
- CVE-2026-47904MEDIUM 6.2
CAI Content Credentials, a component used for managing digital content authenticity and provenance, contains a flaw that allows an attacker to consume excessive system resources without requiring user action. An affected application could become unresponsive or crash, effectively denying legitimate users access to the service. This is a local-level vulnerability, meaning an attacker needs some degree of system access to trigger the condition.
- CVE-2026-47905MEDIUM 6.2
A resource exhaustion vulnerability exists in Adobe's Content Credentials (C2PA) library that allows an attacker to consume excessive system resources and crash an application without requiring any user action. The vulnerability affects C2PA Web version 0.7.1 and earlier, as well as C2PA version 0.80.1 and earlier. An unauthenticated attacker with local access could trigger the issue remotely through the affected library, leading to a denial-of-service condition.
- CVE-2026-53465MEDIUM 6.2
ImageMagick, a widely-used image editing and manipulation tool, contains a memory corruption vulnerability in versions before 7.1.2-25. When processing specially crafted multi-frame images using the SF3 encoder, the software can write data beyond allocated memory boundaries, potentially causing application crashes or system instability. This is a local vulnerability requiring no special privileges or user interaction to trigger.
- CVE-2026-54778MEDIUM 6.2
CoreWCF, a .NET Core implementation of Windows Communication Foundation, contains a concurrency flaw in how it resolves user identities for Unix domain socket connections. The vulnerability stems from the use of non-thread-safe system functions (getpwuid and getgrgid) that can cause one client connection to be misidentified as another during simultaneous access, or potentially crash the service. Versions prior to 1.8.1 and 1.9.1 are affected. This is a local attack surface issue affecting systems where CoreWCF processes handle multiple concurrent Unix socket clients.
- CVE-2026-56459MEDIUM 6.2
HCL DevOps Deploy and HCL Launch contain a local information disclosure vulnerability where sensitive data is written to application log files readable by any user on the system. An attacker with local access can read these logs to obtain confidential information, such as credentials, API tokens, or deployment secrets. This is a local-only attack that does not require authentication or user interaction.
- CVE-2026-58300MEDIUM 6.2
Microsoft Edge for Android contains a path traversal vulnerability that allows an attacker with local access to the device to read sensitive files. The vulnerability does not require user interaction or elevated privileges, making it a concern for any Android device running the affected version of Edge. An attacker would need physical or local network access to the device to exploit this issue.
- CVE-2026-8594MEDIUM 6.2
Text::LineFold, a Perl module for handling line breaks in text, contains a bug that causes it to duplicate output when processing strings with certain special break characters (like vertical tabs and form feeds). The module splits input by these characters but then applies its line-breaking logic to the entire original string instead of just the individual segments, resulting in unnecessary duplication. While primarily a logic error, this can cause excessive memory and CPU consumption if exploited, potentially leading to denial of service on systems processing untrusted text input.
- CVE-2026-9073MEDIUM 6.2
Foreman-mcp-server contains two logging flaws that can expose authentication secrets. Session identifiers are logged as informational messages, and when debug logging is enabled, HTTP headers containing authorization tokens and API keys are not properly sanitized before being written to logs. These plaintext credentials in container logs create a confidentiality risk, especially if logs are shipped to centralized logging systems where they may be accessed by additional parties.
- CVE-2026-9260MEDIUM 6.2
Canon EOS Network Setting Tool version 1.5.0 and earlier contains hard-coded cryptographic keys that are embedded directly in the application binary. An attacker with local access to an affected system can extract these keys and use them to decrypt or forge network communications intended to be protected by encryption. This is a confidentiality risk that does not require user interaction to exploit.
- CVE-2019-25731MEDIUM 6.1
Zuz Music version 2.1 has a flaw that lets anyone send malicious code through the contact form without needing to log in. When site administrators read these messages, the injected code runs in their browsers, potentially allowing attackers to steal session data, modify settings, or trick them into performing unwanted actions. This is a persistent vulnerability, meaning the malicious payload stays stored on the server and affects every admin who views the inbox.
- CVE-2019-25737MEDIUM 6.1
Live Chat Unlimited version 2.8.3 contains a stored cross-site scripting (XSS) vulnerability in its chat input field. An unauthenticated attacker can inject malicious JavaScript code that persists in the system and executes when administrators access the chat interface. This allows attackers to steal admin session cookies, redirect users to phishing sites, or perform unauthorized actions within the admin dashboard without requiring authentication.
- CVE-2025-40808MEDIUM 6.1
Siemens SIPROTEC 5 protective relays contain a file upload vulnerability affecting dozens of device models across multiple control processor variants. An authenticated attacker can upload malicious configuration files through the DIGSI 5 protocol, potentially disrupting power system operations or executing unauthorized code. The vulnerability requires valid credentials but represents a meaningful risk in environments where multiple operators or contractors have access to device management interfaces.
- CVE-2025-60465MEDIUM 6.1
A use-after-free memory vulnerability exists in GPAC's media file processing logic. When MP4Box or the GPAC library processes a specially crafted media file, it can access memory that has already been freed, triggering a crash. An attacker needs only to trick a user into opening a malicious file locally—no network interaction required. The impact is denial of service; while the vulnerability does involve memory corruption, the specific attack vector does not lead to code execution in the current configuration.
- CVE-2025-71331MEDIUM 6.1
Flowise, a platform for building AI chat applications, has a cross-site scripting (XSS) weakness in versions before 3.0.8. An attacker can inject malicious code through chat messages or custom agent functions, which then runs in a victim's browser when they interact with an affected Flowise instance. This could allow theft of session cookies and authentication tokens, potentially giving attackers unauthorized access to user accounts or sensitive data the victim can access.
- CVE-2025-71385MEDIUM 6.1
Netdata versions before 2.3.1 contain a reflected cross-site scripting (XSS) vulnerability in two undocumented SVG endpoints. These endpoints (`/api/v2/ilove.svg` and `/api/v3/ilove.svg`) accept a user-supplied `love` query parameter and insert it directly into an SVG document without any sanitization. An attacker can craft a malicious URL containing JavaScript code, and when a victim visits that URL, the script executes in their browser with access to the Netdata instance's origin. Because these endpoints are accessible without authentication on default Netdata deployments, no special access is required to exploit this vulnerability.
- CVE-2025-8591MEDIUM 6.1
CVE-2025-8591 is a reflected cross-site scripting (XSS) vulnerability affecting multiple WSO2 products. An attacker can craft a malicious URL containing script code that, when clicked by a user, executes arbitrary JavaScript in the victim's browser. While session cookies are protected by httpOnly flags (preventing token theft), an attacker can still redirect users to phishing sites, deface page content, or harvest non-sensitive browser data. The vulnerability requires user interaction—the victim must click a crafted link—making it a social engineering vector rather than a wormable flaw.
- CVE-2026-0279MEDIUM 6.1
Palo Alto Networks PAN-OS contains multiple cross-site scripting (XSS) vulnerabilities in its User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN components. An unauthenticated attacker can inject malicious JavaScript that either persists in the system or executes in a user's browser. The vulnerability requires user interaction (such as clicking a malicious link) to trigger. Palo Alto's deployment best practices—restricting management interface and Authentication Portal access to trusted internal IP addresses—significantly reduce exposure.
- CVE-2026-10305MEDIUM 6.1
Samsung's rlottie animation library contains a vulnerability that allows reading data beyond the intended buffer boundaries. When processing specially crafted animation files, the library may access memory it shouldn't, potentially exposing sensitive information or causing the application to crash. The issue stems from insufficient bounds checking during buffer operations. While the vulnerability requires user interaction (opening a malicious animation file) and is limited to local access, the combination of integrity impact and high availability risk warrants prompt attention.
- CVE-2026-10510MEDIUM 6.1
A cross-site scripting (XSS) vulnerability exists in the GeniexWebView component of Transsion's AI Assistant Lifestyle application for Android. An attacker can craft a malicious URL containing injected JavaScript code in the web_action_data parameter, which the vulnerable WebView will execute with the same privileges as the application. This allows arbitrary JavaScript execution in the context of the app, potentially compromising user data or enabling phishing attacks. The vulnerability affects all versions of the application currently in distribution.
- CVE-2026-10856MEDIUM 6.1
MISP dashboard widgets contain a URL validation flaw that allows attackers to craft malicious buttons appearing to link within the application while actually redirecting users to external sites. The vulnerability stems from incomplete validation that accepts paths like '/\example.com', which browsers may normalize into scheme-relative URLs pointing to attacker-controlled domains. An attacker with dashboard configuration access can embed these crafted buttons to redirect legitimate users, creating phishing and credential-theft opportunities.
- CVE-2026-10857MEDIUM 6.1
A reflected cross-site scripting (XSS) vulnerability exists in AKIN Software's E-Commerce platform versions prior to 1.25.01.06. The flaw allows an attacker to inject malicious scripts into web pages viewed by users, potentially compromising user sessions, stealing credentials, or performing unauthorized actions on behalf of the victim. The attack requires user interaction—specifically clicking a crafted link—but does not require authentication.
- CVE-2026-10861MEDIUM 6.1
MISP, a widely-used threat intelligence sharing platform, contains an open redirect vulnerability in its post-login redirect logic. When a user logs in, the application redirects them to a URL stored in the session without properly validating that the destination is actually part of the MISP application. An attacker can craft a malicious link that tricks users into visiting their legitimate MISP instance, then redirects them to an attacker-controlled website after they authenticate. This could be weaponized for phishing by appearing to come from a trusted source or to deliver malware from a domain the victim might not otherwise visit.
- CVE-2026-10916MEDIUM 6.1
CVE-2026-10916 is a cross-site scripting vulnerability in Google Chrome's developer tools that allows an attacker to inject malicious scripts or HTML content into a webpage. The attack requires two conditions: first, the attacker must have already compromised Chrome's renderer process (the component that executes web content), and second, the user must be tricked into visiting a specially crafted HTML page. While the initial compromise is a significant prerequisite, once achieved, this vulnerability enables the attacker to execute arbitrary code with the privileges of the browser session, potentially stealing sensitive data or performing actions on behalf of the user.
- CVE-2026-11034MEDIUM 6.1
Google Chrome on Android contains a vulnerability in its Tab Group Sync feature that allows attackers to inject malicious scripts or HTML into web pages. An attacker with network access can craft malicious traffic to exploit insufficient input validation, potentially displaying fake content or stealing user information from websites. This affects Chrome versions prior to 149.0.7827.53.
- CVE-2026-11122MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how the keyboard input handler processes certain HTML page elements. An attacker can craft a malicious webpage that, when visited by an unsuspecting user, injects arbitrary scripts or HTML content that executes in a security context where it shouldn't be allowed—a technique called Uniform Cross-Site Scripting (UXSS). This bypasses the browser's same-origin policy protections that normally prevent cross-domain attacks. The vulnerability requires user interaction (clicking or viewing the page) but affects all major platforms where Chrome runs.
- CVE-2026-11150MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects arbitrary scripts or HTML content that execute in the context of unrelated sites (a technique known as Universal Cross-Site Scripting or UXSS). This bypasses the same-origin policy that normally prevents one site from accessing data or performing actions on another. The vulnerability requires user interaction—a victim must visit the attacker's page—but does not require any special browser configuration or user privileges to trigger.
- CVE-2026-11186MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in CSS handling that allows attackers to inject malicious scripts or HTML into web pages users visit. An attacker would craft a specially designed webpage that, when opened in a vulnerable version of Chrome, bypasses security boundaries and executes unauthorized code in the context of other websites. This type of attack, known as Universal XSS (UXSS), is particularly dangerous because it affects the browser itself rather than individual websites, potentially compromising user data across multiple domains.
- CVE-2026-11205MEDIUM 6.1
Google Chrome on iOS versions prior to 149.0.7827.53 contain a vulnerability that allows attackers to inject malicious scripts or HTML into web pages through crafted QR codes. The attack requires user interaction—specifically, the victim must engage with certain UI gestures in response to the attacker's QR code—but once triggered, the injected content runs with the privileges of the page being viewed. This is a cross-origin scripting (UXSS) issue, meaning the injected code can affect pages from different origins, potentially stealing session cookies, credentials, or sensitive data.
- CVE-2026-11229MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how the application handles certain enterprise features that could allow someone with physical access to your device to gain elevated privileges. The vulnerability requires an attacker to be present at the machine itself and does not need you to take any action—they can exploit it directly. This is a local-only threat and cannot be exploited remotely over the internet.
- CVE-2026-11273MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a vulnerability in the Omnibox (the address/search bar) that fails to properly validate user input. An attacker can craft a malicious HTML page that, when visited by a user who interacts with the Omnibox through specific UI actions, allows injection of arbitrary scripts or HTML content. This is a cross-site scripting variant (UXSS) that bypasses the normal security boundary between web pages. The attack requires user interaction and social engineering to be effective, but once triggered, can compromise the integrity and confidentiality of the browsing session.
- CVE-2026-11392MEDIUM 6.1
The WP Hotel Booking plugin for WordPress contains a Reflected Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker can craft a specially designed link containing malicious code in the check-in or check-out date parameters. If a site user clicks that link, the injected script executes in their browser, potentially stealing credentials, session tokens, or performing actions on their behalf. This vulnerability affects all versions up to and including 2.3.1 and requires no special privileges to exploit—only user interaction.
- CVE-2026-11603MEDIUM 6.1
A reflected cross-site scripting (XSS) vulnerability exists in the Product Filter Widget for Elementor WordPress plugin through version 1.0.6. An attacker can craft a malicious link and trick a user into clicking it, causing arbitrary JavaScript to execute in the victim's browser within the context of their WordPress site. The vulnerability stems from the plugin's failure to properly sanitize user input in the 'args[filterFormArray]' parameter before displaying it back to the user. No authentication is required to exploit this flaw, and the attack is delivered silently via an admin-ajax.php endpoint without requiring verification that the request is legitimate.
- CVE-2026-11798MEDIUM 6.1
The Super Socializer WordPress plugin—a widely-used tool for social sharing, login, and comment features—contains a reflected cross-site scripting (XSS) vulnerability in versions up to 7.14.5. An attacker can craft a malicious link containing injected JavaScript code in the 'heateor_mastodon_share' parameter. If a user clicks that link while logged into their WordPress site, the malicious script executes in their browser with their privileges, potentially stealing session data, modifying content, or performing unauthorized actions. This requires social engineering—the attacker must trick the user into clicking—but requires no special privileges or technical user action beyond a click.
- CVE-2026-11878MEDIUM 6.1
OpenText Access Manager versions 5.1 through 5.1.2 contain a cross-site scripting (XSS) vulnerability in web page generation. An attacker can inject malicious JavaScript code that executes in the browsers of users accessing the affected system. The vulnerability requires user interaction (such as clicking a crafted link) but does not require authentication, making it accessible to unauthenticated threat actors. While not currently listed in CISA's Known Exploited Vulnerabilities catalog, the combination of network accessibility and user-triggered execution means organizations should prioritize remediation.
- CVE-2026-12137MEDIUM 6.1
A reflected cross-site scripting (XSS) vulnerability exists in the SysBasics Customize My Account for WooCommerce plugin for WordPress. The flaw is in how the plugin handles the 'tab' parameter—it fails to properly sanitize and escape user input before displaying it on the admin dashboard. An attacker can craft a malicious link containing JavaScript code that executes in the browser of any logged-in Shop Manager or administrator who clicks it. The attack requires social engineering (tricking a user into clicking a link) and a valid WordPress admin session, but poses a real risk to compromised user accounts or credential-based attacks.
- CVE-2026-12425MEDIUM 6.1
PowerSchool Employee Access Center version 23.10 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code into login URLs. When a user clicks a crafted link, the injected code executes in their browser with their privileges, potentially enabling session hijacking, credential theft, or unauthorized actions on their behalf.
- CVE-2026-12459MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.155 contain a vulnerability in the Serial component that allows attackers to inject malicious scripts or HTML into web pages through a specially crafted HTML file. The attack requires user interaction (clicking or otherwise engaging with the malicious page) but does not require the victim to have special privileges. The injected content can compromise page integrity and access sensitive user data within the affected browser context.
- CVE-2026-12479MEDIUM 6.1
A flaw in Keras 3.14.0's model saving and loading functionality allows an attacker to use specially crafted layer names to write files or create directories outside the intended temporary working directory. While the code blocks forward slashes in layer names, it doesn't sanitize directory traversal sequences like `..`, enabling path escape. An attacker must trick a user into saving or loading a malicious model file for exploitation to occur.
- CVE-2026-12754MEDIUM 6.1
The VikBooking Hotel Booking Engine & PMS plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions up to 1.8.12. An attacker can craft a malicious link containing JavaScript code in the 'layoutstyle' parameter. If a user clicks that link while viewing a page with the vulnerable [vikbooking view="roomslist"] shortcode, the attacker's script executes in the user's browser in the context of that website. This could allow credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (clicking a link) and only affects pages that use the specific shortcode.
- CVE-2026-13015MEDIUM 6.1
The Wp Google Places Review Slider plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions 18.1 and earlier. An attacker can craft a malicious link containing JavaScript code in the 'place' parameter. When a site administrator or authorized user clicks this link, the injected script executes in their browser within the context of the WordPress admin panel, potentially allowing the attacker to steal credentials, modify site content, or perform other unauthorized actions on behalf of the victim.
- CVE-2026-13245MEDIUM 6.1
The MaxButtons – Create buttons plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions up to 9.8.5. An attacker can craft a malicious link containing JavaScript code that executes in a victim's browser when they click it. Because the plugin doesn't properly sanitize the 'view' parameter, the injected script runs in the context of the WordPress site, potentially allowing the attacker to steal session tokens, modify page content, or perform actions on behalf of the victim. This requires social engineering—the attacker must trick someone into clicking a crafted link—but no user authentication is needed to create the attack.
- CVE-2026-13334MEDIUM 6.1
The Mang Board plugin for WordPress has a flaw that allows attackers to inject malicious code into web pages. An unauthenticated attacker can craft a deceptive link containing malicious script in the 'stag' parameter. When a user clicks the link, the injected script runs in their browser, potentially stealing session cookies, credentials, or performing actions on their behalf. The vulnerability affects all versions up to 2.3.4.
- CVE-2026-13836MEDIUM 6.1
Google Chrome versions before 150.0.7871.47 contain a CSS handling flaw that allows attackers to inject malicious scripts or HTML into pages you visit. An attacker would craft a deceptive webpage and trick you into opening it; the browser's CSS parser would then execute the attacker's code in the context of a legitimate site you trust. This is a 'universal cross-site scripting' (UXSS) vulnerability—more severe than typical XSS because it bypasses the normal boundaries between websites.
- CVE-2026-14000MEDIUM 6.1
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects unauthorized scripts or HTML content that executes with the privileges of the current webpage—a technique known as Unintended Cross-Site Scripting (UXSS). This allows attackers to steal data, manipulate page content, or perform actions on behalf of the user without additional user interaction beyond viewing the page.
- CVE-2026-14001MEDIUM 6.1
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles network-related content that allows attackers to inject malicious scripts or HTML code into web pages you visit. An attacker would craft a specially designed webpage; when you visit it, the injected code runs in your browser with the privileges of the website you're viewing, potentially stealing data or performing actions on your behalf. This type of attack, known as UXSS (Universal XSS), bypasses Chrome's normal security boundaries.
- CVE-2026-14068MEDIUM 6.1
Google Chrome on iOS contains a flaw in how it handles the Omnibox (address bar) that can allow an attacker to inject malicious scripts or HTML content into a webpage you're viewing. The vulnerability requires a user to perform specific gestures in the browser interface—such as interacting with the address bar in a particular way—after visiting a specially crafted webpage. This is a cross-site scripting variant (UXSS) that affects Chrome versions before 150.0.7871.47 on iOS devices.
- CVE-2026-14083MEDIUM 6.1
Google Chrome versions before 150.0.7871.47 contain a vulnerability that allows attackers to inject malicious scripts or HTML into web pages through insufficient input validation. An attacker would need to trick a user into visiting a specially crafted webpage, but once successful, the injected code can run with the same privileges as the visited site, potentially stealing session data, modifying page content, or performing actions on behalf of the user.
- CVE-2026-14145MEDIUM 6.1
Google Chrome versions prior to 150.0.7871.47 contain a vulnerability in how CSS (Cascading Style Sheets) is processed that allows attackers to inject malicious scripts or HTML content into web pages. An attacker would need to trick a user into visiting a specially crafted webpage; if successful, the injected code runs with the privileges of the visited site, potentially compromising user data or enabling further attacks. This is classified as a Universal XSS (UXSS) vulnerability, meaning the attack bypasses normal browser security boundaries.
- CVE-2026-14147MEDIUM 6.1
Google Chrome versions before 150.0.7871.47 contain a flaw in CSS handling that allows an attacker to inject malicious scripts or HTML into web pages viewed by users. The vulnerability requires user interaction (clicking a link or visiting a crafted page) and affects the security boundary between websites, potentially allowing one site to compromise another or steal sensitive data. While Chromium classified this as low severity internally, the cross-site nature of the exploit and the ease of triggering it via a simple crafted HTML page elevate the practical risk.
- CVE-2026-14358MEDIUM 6.1
The Wikimedia Foundation's MediaWiki Charts Extension contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker can craft a specially designed chart parameter or input that, when processed by the extension, executes arbitrary JavaScript in the browsers of users viewing that content. This requires user interaction—specifically, a user must view the affected page—but does not require authentication. The vulnerability affects multiple version branches of the Charts Extension and has been patched in versions 1.43.9, 1.44.6, and 1.45.4.
- CVE-2026-1450MEDIUM 6.1
The rognone WordPress plugin contains a reflected cross-site scripting (XSS) flaw that allows unauthenticated attackers to inject malicious scripts into web pages. The vulnerability exists in how the plugin handles the 'mode' parameter—it fails to properly sanitize user input and escape output, creating an opening for attackers to craft malicious links. If a user clicks such a link while using a site running the vulnerable plugin, the attacker's script executes in their browser with access to session data and sensitive information.
- CVE-2026-1451MEDIUM 6.1
The rognone plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into pages viewed by unsuspecting users. An attacker could craft a malicious link containing JavaScript in the 'a' parameter and trick a user into clicking it, causing the script to execute in their browser within the context of the WordPress site. This works because the plugin fails to properly sanitize user input or escape output before displaying it. The vulnerability affects versions up to and including 0.6.2.
- CVE-2026-15127MEDIUM 6.1
A flaw in how Google Chrome handles WebGL—a web technology for rendering graphics—allows attackers to inject malicious scripts or HTML into pages you visit. An attacker could craft a deceptive webpage that, when opened in a vulnerable Chrome browser, executes unauthorized code with the privileges of the web page you're viewing. This is a form of cross-site scripting (XSS) attack. The vulnerability affects Chrome versions prior to 150.0.7871.115.
- CVE-2026-15128MEDIUM 6.1
A flaw in how Google Chrome handles web forms before version 150.0.7871.115 allows attackers to inject malicious scripts or HTML into pages viewed by users. An attacker would craft a specially designed webpage and trick a user into visiting it, at which point the injected code runs in the user's browser with access to sensitive page content. This is a cross-site scripting (XSS) variant that bypasses normal browser protections.
- CVE-2026-15297MEDIUM 6.1
The Brevo email marketing plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions up to 3.1.77. An attacker can craft a malicious link containing injected scripts that execute in a victim's browser if the victim clicks the link while logged into WordPress. The vulnerability stems from the plugin's failure to properly sanitize and escape user input in the 'page' parameter. No authentication is required to exploit this, and the attack relies on social engineering—tricking a user into clicking a malicious link.
- CVE-2026-20175MEDIUM 6.1
A remote attacker can trick a user into clicking a malicious link that causes their browser to load files from an attacker-controlled location while interacting with Cisco Finesse. Because the application doesn't properly validate where those files come from, an attacker can inject malicious scripts or steal sensitive information visible in the user's active session—all without needing to authenticate first.
- CVE-2026-20233MEDIUM 6.1
Cisco Webex Meetings contained a cross-site scripting (XSS) vulnerability in its web interface that could allow an attacker to inject malicious scripts if a user clicked a crafted link. The vulnerability resulted from weak input validation. Cisco has already patched the service, and users do not need to take action—the fix has been deployed automatically.
- CVE-2026-21825MEDIUM 6.1
HCL Digital Experience and Digital Experience Compose contain a reflected cross-site scripting (XSS) vulnerability in their search center functionality. An attacker can craft a malicious link containing JavaScript code and trick a user into clicking it. When the victim visits the link, the attacker's script executes in their browser with their privileges, potentially stealing session cookies, credentials, or performing actions on their behalf. This vulnerability requires user interaction—the victim must click a malicious link—which somewhat limits its reach, but the ability to target any user makes it a meaningful risk for organizations relying on these platforms.
- CVE-2026-21826MEDIUM 6.1
HCL Digital Experience and HCL Digital Experience Compose contain a host header injection vulnerability that allows an attacker to manipulate how the application processes the Host header in HTTP requests. By injecting a malicious Host value, an attacker can trigger unexpected application behavior, potentially leading to phishing attacks, cache poisoning, or credential theft. The vulnerability requires user interaction—such as clicking a malicious link—to be exploited, which moderates the overall risk profile.
- CVE-2026-2425MEDIUM 6.1
The hiWeb Migration Simple WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in how it handles the 'new_domain' parameter. An attacker can craft a malicious link and trick a WordPress administrator into clicking it, causing arbitrary JavaScript to execute in the admin's browser session. This could allow the attacker to steal session tokens, modify site content, or perform administrative actions on behalf of the compromised admin. The vulnerability affects all versions through 2.0.0.1.
- CVE-2026-25688MEDIUM 6.1
Apache Answer versions through 2.0.0 contain a cross-site scripting (XSS) vulnerability in how AI-generated response content is displayed to users. When Answer generates responses using AI, the application fails to properly clean this content before showing it in the browser. This allows an attacker to inject malicious scripts that execute in a user's browser when they view the generated response. The vulnerability requires user interaction (clicking a link or viewing a page with the malicious content) but can affect multiple users if the generated response is shared or cached.
- CVE-2026-25699MEDIUM 6.1
Apache Answer versions up to 2.0.0 contain an authorization bypass in timeline-related APIs that allows any authenticated user to view content they shouldn't have access to—including deleted items, private submissions, and unapproved materials, along with their full revision history. An attacker with a regular user account can exploit this by directly calling these APIs without needing elevated privileges. The vendor has released version 2.0.1 to address the flaw.
- CVE-2026-25779MEDIUM 6.1
Gitea, a self-hosted Git service, contains a redirect validation flaw that allows attackers to bypass intended redirect protections by embedding raw or percent-encoded backslashes in redirect_to parameters. This enables attackers to redirect users to untrusted external sites after authentication, potentially leading to credential theft or phishing. The vulnerability affects Gitea versions 1.25.4 and earlier.
- CVE-2026-25860MEDIUM 6.1
OpenClinic GA version 5.351.19 contains a reflected cross-site scripting (XSS) vulnerability in its DICOM image upload functionality. An attacker can craft a malicious DICOM medical image file containing JavaScript code in metadata fields like Study Description. When a user uploads and processes this file through the application's DICOM upload feature, the embedded script executes in their browser without restriction, potentially allowing the attacker to steal session cookies, redirect users to malicious sites, or perform unauthorized actions on behalf of the victim.
- CVE-2026-29170MEDIUM 6.1
Apache HTTP Server versions 2.4.67 and earlier contain a cross-site scripting (XSS) vulnerability in the mod_proxy_ftp module. When the server is configured to proxy FTP directory listings—whether forwarding traffic to an upstream FTP server or presenting one via reverse proxy—it fails to properly sanitize HTML generated for directory contents. An attacker can craft malicious FTP directory entries or filenames containing JavaScript code. When an administrator or user views the directory listing in a browser, the malicious script executes in their session, potentially allowing session hijacking, credential theft, or administrative actions.
- CVE-2026-30586MEDIUM 6.1
A cross-site scripting (XSS) vulnerability exists in usememos Memos version 0.26.0 that allows an attacker to inject malicious code into memo pages. When a user views a compromised memo—whether public or private—the attacker's script executes in the user's browser, potentially exposing sensitive information. The vulnerability stems from improper sanitization of user input in the memo rendering component, meaning the application fails to adequately strip or encode dangerous HTML and JavaScript before displaying memo content.
- CVE-2026-32856MEDIUM 6.1
Ellucian Banner Self-Service is vulnerable to a reflected cross-site scripting (XSS) attack before its April T2 2025 release. An attacker can craft a malicious URL and send it to an unauthenticated user. When clicked, the URL injects malicious JavaScript into the victim's browser through an unsanitized parameter in the dateConverter endpoint. This could allow the attacker to steal session cookies, hijack accounts, or perform actions on behalf of the victim.
- CVE-2026-33553MEDIUM 6.1
Northern.tech CFEngine Enterprise contains a cross-site scripting (XSS) vulnerability in versions 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1. An attacker can inject malicious scripts that execute in the browser context of users interacting with the CFEngine Enterprise interface, potentially compromising user sessions or stealing sensitive information without requiring authentication.
- CVE-2026-34416MEDIUM 6.1
OSCAL-GUI contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to execute malicious JavaScript in users' browsers without authentication. An attacker crafts a deceptive URL containing specially crafted input in the project request parameter. When a victim clicks the link, the malicious payload executes in their browser, bypassing security filters. This attack requires social engineering—tricking someone into clicking a malicious link—but the impact can include session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.
- CVE-2026-34417MEDIUM 6.1
OSCAL-GUI contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into a victim's browser. An unauthenticated attacker can craft a malicious URL containing JavaScript code in the project request parameter. When a victim visits this URL, the injected code executes in their browser with the same privileges as the victim, potentially allowing attackers to steal session cookies, perform actions on behalf of the user, or redirect them to phishing sites. The vulnerability requires user interaction—specifically clicking a malicious link—but no authentication is required to exploit it.
- CVE-2026-34915MEDIUM 6.1
Revive Adserver versions up to 6.0.6 contain a vulnerability in the zone-include.php script where user input is not properly validated before being used in database queries. An attacker with low privileges can manipulate the clientid parameter to inject malicious SQL commands, potentially reading or modifying sensitive data in the database. The attack does not require special access rights and is triggered via a web request, though user interaction is needed for successful exploitation.
- CVE-2026-35212MEDIUM 6.1
OpenCTI, an open-source threat intelligence platform, contains a cross-site scripting (XSS) vulnerability in how it renders email message data. An attacker can craft a malicious email observable with unsanitized content in the message body, which executes JavaScript in a victim's browser when they view it. Because threat intelligence is often shared across teams via STIX files or automated ingesters, this could be weaponized to steal session cookies at scale, potentially compromising multiple analysts' accounts. The vulnerability requires user interaction—someone must view the crafted email observable—but the attack surface is broad given how threat intelligence is typically distributed.
- CVE-2026-36324MEDIUM 6.1
SourceCodester Doctor Appointment System version 1.0 contains a Cross-Site Scripting (XSS) vulnerability in its user registration form. An attacker can inject malicious scripts into the registration page, which are then executed in the browsers of other users who view that registration data. This allows the attacker to steal session cookies, redirect users to phishing sites, or perform actions on behalf of legitimate users without their knowledge.
- CVE-2026-36521MEDIUM 6.1
PublicCMS V5.202506.d contains a cross-site scripting (XSS) vulnerability in its site configuration management module. An attacker can inject malicious scripts into the configuration interface, which are then executed in the browsers of administrators and other users who view the affected settings. This allows attackers to steal session tokens, redirect users to phishing sites, or perform unauthorized administrative actions without requiring authentication to the CMS itself.
- CVE-2026-36725MEDIUM 6.1
FastapiAdmin version 2.2.0 contains a vulnerability where attackers can inject malicious scripts into system notices. When an administrator or authorized user views a crafted notice through the notice creation endpoint, the injected code executes in their browser, potentially allowing attackers to steal session tokens, modify page content, or perform actions on their behalf. The attack requires user interaction—the victim must view the malicious notice—but no authentication is needed to craft and inject the payload.
- CVE-2026-37216MEDIUM 6.1
Ruoyi version 4.8.2 contains a cross-site scripting (XSS) vulnerability in its system notice creation interface. An attacker can inject malicious JavaScript code through the /system/notice/add endpoint, which will execute in the browsers of users who view the crafted notice. This vulnerability requires user interaction—specifically, a victim must view a notice containing the malicious payload—but does not require authentication to create the notice. The impact is limited to information disclosure and minor modifications visible to end-users; system availability is not affected.
- CVE-2026-38579MEDIUM 6.1
Damasac Thaipalliative LTE through version 3.0 contains multiple reflected cross-site scripting (XSS) vulnerabilities that allow attackers to inject malicious scripts into web pages viewed by users. The flaws exist in the /substudy/ezform.php file where user-supplied values are directly inserted into HTML without proper sanitization. An attacker can craft a malicious URL and trick a user into clicking it, causing arbitrary JavaScript to execute in that user's browser within the context of the vulnerable application.
- CVE-2026-39897MEDIUM 6.1
Cacti, an open-source monitoring and performance management platform, contains a reflected cross-site scripting (XSS) vulnerability in its authentication footer component. An attacker can craft a malicious link that, when clicked by a user, injects arbitrary JavaScript into the victim's browser session. This could allow theft of session cookies, credential harvesting, or redirection to phishing sites. The vulnerability affects Cacti versions 1.2.30 and earlier; version 1.2.31 and later contain the fix.
- CVE-2026-39900MEDIUM 6.1
Cacti, a widely-used open source tool for monitoring network performance and managing faults, has a reflected cross-site scripting (XSS) vulnerability in its auth_profile.php file. An attacker can craft a malicious link containing JavaScript code in the 'tab' parameter that executes in a victim's browser when they click it. The victim must be tricked into clicking the link, but once they do, the attacker gains the ability to steal session tokens, alter page content, or perform actions on behalf of the logged-in user. Cacti versions 1.2.30 and earlier are vulnerable; version 1.2.31 fixes the issue.
- CVE-2026-40080MEDIUM 6.1
Cacti, a widely-used open-source monitoring framework, contains an open redirect vulnerability in its authentication flow. When users log in with the referer-redirect option enabled, the application fails to properly validate where it sends them after login. An attacker can craft a malicious login link that appears to reference your Cacti installation but actually redirects to an attacker-controlled site. This allows phishing attacks: an attacker could send a fake login request that looks legitimate, capture credentials, and then silently hand the user off to a malicious domain. The vulnerability affects Cacti version 1.2.30 and earlier; it is patched in version 1.2.31.
- CVE-2026-40181MEDIUM 6.1
React Router, a widely-used navigation library for React applications, contains an open redirect vulnerability in specific versions. When certain URLs are passed to the redirect function, the library can inadvertently send users to an external website controlled by an attacker. This happens because paths beginning with double slashes (//) are misinterpreted as protocol-relative URLs, allowing an attacker to craft a malicious URL that bypasses the intended redirect destination. The vulnerability only affects applications using the programmatic redirect function; applications built with React Router's declarative mode (using <BrowserRouter>) are not impacted. The severity of the risk depends on how thoroughly the application validates URLs before redirecting.
- CVE-2026-40713MEDIUM 6.1
Dell ThinOS 10 devices running versions before 2602_10.0765 have a flaw that allows someone with physical access to the device—without needing to log in—to view sensitive information stored on it. This is a medium-severity issue because it requires hands-on access to the hardware, but once someone has that access, the controls meant to protect data don't work properly.
- CVE-2026-41008MEDIUM 6.1
Spring Security Authorization Server contains an open redirect vulnerability in its authorization endpoint. When processing OAuth 2.0 authorization requests, the server insufficiently validates the request_uri parameter, allowing an attacker to combine an invalid request_uri with a crafted redirect_uri to redirect users to an attacker-controlled website after authentication. This affects Spring Security versions 7.0.0–7.0.5 and Spring Authorization Server versions 1.5.0–1.5.7.
- CVE-2026-4110MEDIUM 6.1
A reflected cross-site scripting (XSS) vulnerability exists in the ultimate-woocommerce-auction-pro WordPress plugin versions up to 2.4.5. The plugin fails to properly sanitize and escape user-supplied input before displaying it in the page, allowing an attacker to inject malicious scripts. Because the vulnerability requires user interaction (clicking a crafted link) and can target high-privilege users like administrators, it poses a meaningful risk to WordPress installations using this plugin.
- CVE-2026-41539MEDIUM 6.1
QNAP has patched a cross-site scripting (XSS) vulnerability affecting multiple versions of QTS and QuTS hero operating systems. The flaw allows remote attackers to inject malicious scripts that execute in users' browsers, potentially bypassing security controls or stealing sensitive application data. No authentication is required to attempt exploitation, but a user must be tricked into clicking a malicious link or visiting a compromised page. QNAP has released security updates addressing the issue across affected product lines.
- CVE-2026-41568MEDIUM 6.1
A race condition vulnerability in Docker Engine and Moby allows a malicious container to create empty files or directories at arbitrary locations on the host filesystem during the docker cp operation. An attacker with container access can exploit a timing window in mount setup to place files outside intended boundaries, potentially disrupting host operations or creating persistent artifacts. The vulnerability requires local access and user interaction, limiting but not eliminating real-world risk in multi-tenant or supply-chain scenarios.
- CVE-2026-41569MEDIUM 6.1
authentik, an open-source identity provider, contains a URL validation flaw in its WS-Federation provider that allows attackers to redirect users' login credentials to attacker-controlled domains. The vulnerability stems from incomplete validation of the wreply parameter—a redirect URL used after authentication. An attacker can craft a malicious login link where the wreply parameter points to a lookalike domain (for example, https://portal.example.com.evil.tld/) that bypasses the validation check, tricking users into sending their signed authentication response to the attacker instead of the legitimate application. This affects authentik versions prior to 2026.2.3.
- CVE-2026-41706MEDIUM 6.1
Spring Security's request caching mechanisms (CookieRequestCache and CookieServerRequestCache) contain an open redirect vulnerability. These components store the URL users intended to visit before logging in, then redirect them there after successful authentication. The vulnerability exists because the stored URL is not validated before being used as a redirect target, allowing attackers to craft malicious login links that redirect authenticated users to arbitrary external websites. An attacker could exploit this to perform phishing attacks, credential harvesting, or malware distribution by tricking users into clicking a specially crafted link.
- CVE-2026-41715MEDIUM 6.1
Reactor Netty, a popular HTTP client library, has a credential leakage vulnerability that occurs when the client automatically follows HTTP redirects that go from a secure (HTTPS) endpoint to an insecure (HTTP) one. When this happens, authentication credentials can be transmitted in the clear over the unencrypted connection. The vulnerability only manifests in applications that have explicitly enabled redirect-following behavior. This is a configuration-dependent issue: systems using default settings or those that do not follow redirects are unaffected.
- CVE-2026-42253MEDIUM 6.1
Apache ActiveMQ's web console contains a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious content into HTTP response headers. The flaw exists in how the MessageServlet handles JMS message properties—it copies them directly into HTTP headers without filtering or validation. An attacker who can craft a JMS message with specially crafted properties could inject security headers, potentially leading to session hijacking, credential theft, or malware delivery when a user views the affected web console. The vulnerability requires user interaction (a victim must view the injected content) and affects versions of ActiveMQ and ActiveMQ Web released before 5.19.7 and 6.2.6.
- CVE-2026-42573MEDIUM 6.1
Svelte, a lightweight and performance-focused web framework, contained a vulnerability in versions before 5.55.7 that allowed attackers to manipulate the browser's DOM in a way that corrupted Svelte's internal state. By exploiting DOM clobbering—a technique where attackers inject HTML elements that shadow legitimate JavaScript objects—an attacker could potentially inject malicious scripts that execute in a user's browser, leading to cross-site scripting (XSS) attacks. The vulnerability requires user interaction, such as clicking a link or visiting a malicious page, to be triggered.
- CVE-2026-42599MEDIUM 6.1
Svelte, a popular web framework, contains a vulnerability where untrusted data rendered as HTML attributes can include malicious event handlers. If your application uses Svelte's spread syntax to render attributes from user input or external sources, attackers could inject code that runs when users interact with those elements. The risk is reduced if Svelte's hydration process completes before the injected event fires, but this shouldn't be relied upon as a defense. Version 5.55.7 and later address this issue.
- CVE-2026-4322MEDIUM 6.1
A reflected cross-site scripting (XSS) vulnerability has been discovered in Destekz, a web design and digital advertising platform used by Raera, an Ankara-based agency. The flaw allows attackers to inject malicious scripts into web pages viewed by users. When a victim clicks a specially crafted link, the attacker's code runs in their browser with access to sensitive information like session cookies or personal data. Importantly, the vendor has confirmed the product is no longer supported, meaning no patches will be issued.
- CVE-2026-44644MEDIUM 6.1
LiquidJS, a popular template engine used in Shopify and GitHub Pages, contains a cross-site scripting (XSS) vulnerability in its strip_html filter. This filter is meant to sanitize HTML by removing tags before rendering, but a flaw in its regex pattern allows attackers to bypass it by embedding newline characters within HTML tags. Because browsers treat newlines as whitespace inside tags, malicious event handlers like onerror or onload still execute. Versions 10.25.7 and earlier are affected. The vulnerability requires an attacker to control the input rendered through the vulnerable filter and assumes the application does not separately escape HTML output.
- CVE-2026-44663MEDIUM 6.1
OpenEXR versions 3.4.0 through 3.4.11 contain a flaw in how they process HTJ2K-compressed EXR image files. When decoding a specially crafted file, an integer overflow occurs during calculation of image channel dimensions, resulting in an incorrect memory address. This address is then used to write data to the heap, potentially overwriting adjacent memory. An attacker could exploit this by distributing a malicious EXR file; a user opening it in affected software could experience a crash or, in principle, allow code execution, though the latter is not confirmed. The vulnerability has been patched in version 3.4.12.
- CVE-2026-44746MEDIUM 6.1
SAP NetWeaver JAVA contains a reflected cross-site scripting (XSS) vulnerability in its JDBC Test Servlet component. An attacker can craft a malicious URL containing embedded script code. When an unsuspecting user clicks this link, the script executes in their browser within the context of the affected application. This allows the attacker to steal session data, modify information displayed to the user, or perform unauthorized actions on behalf of the victim—all without requiring the attacker to authenticate or exploit a server-side flaw. The vulnerability requires user interaction (clicking a link) to be triggered.