CVE search
370,878 resultsCVE-2026-54263HIGHWagtail: Reflected XSS in dynamic image URL generator viewEPSS 0.2%CVE-2026-54262MEDIUMWagtail: Pages translations can be created without page permissions when using simple_translationEPSS 0.2%CVE-2026-54261MEDIUMWagtail: Improper permission handling in image previewEPSS 0.2%CVE-2026-54259MEDIUMWagtail: Improper restriction handling on Documents and Images chosen endpointsEPSS 0.2%CVE-2026-54260MEDIUMWagtail: Denial of service via unbounded filter specs in the image previewEPSS 0.2%CVE-2026-14340MEDIUMAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesEPSS 0.2%CVE-2026-54720MEDIUMSilverstripe Framework: Possible XSS attack through media embedEPSS 0.2%CVE-2026-55660HIGHTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeoverEPSS 0.2%CVE-2026-54074HIGH@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labelsEPSS 0.2%CVE-2026-55661MEDIUMTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemesEPSS 0.2%CVE-2026-58263HIGHJodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrierEPSS 0.2%CVE-2026-54756MEDIUMJodit Editor: Prototype pollution via Jodit.configure() / ConfigMergeEPSS 0.3%CVE-2026-55886MEDIUMJodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()EPSS 0.3%CVE-2026-50521HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-54786LOWWasmtime: Leak in WASIp1 `fd_renumber` implementationEPSS 0.2%CVE-2026-55153HIGHmchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"EPSS 0.3%CVE-2026-55688MEDIUMAsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStoreEPSS 0.2%CVE-2026-54908MEDIUMPion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageEPSS 0.3%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.4%CVE-2026-58593HIGHNodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local UserEPSS 0.2%