CVEs from 2026
Total
13,469
critical
critical 1,163
high
high 4,146
medium
medium 4,137
low
low 440
% Critical
8.6%
% with KEV
0.4%
% with exploit
0.5%
Top products
- chrome 417
- firepower_threat_defense 298
- firepower_threat_defense_software 295
- gcp 229
- openclaw 166
- commerce 104
- commerce_b2b 89
- magento 74
Top packages
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-34673 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo… | |||
| CVE-2026-34672 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c… | |||
| CVE-2026-34671 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp… | |||
| CVE-2026-34670 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit … | |||
| CVE-2026-34669 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit … | |||
| CVE-2026-34668 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit … | |||
| CVE-2026-34667 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c… | |||
| CVE-2026-34666 | medium | 6.2 | 6.2 | 17d ago | CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit … | |||
| CVE-2026-42045 | medium | 6.2 | 6.2 | 18d ago | LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution | |||
| CVE-2026-41614 | medium | 6.2 | 6.2 | 18d ago | <p>Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.</p> | |||
| CVE-2026-40380 | medium | 6.2 | 6.2 | 18d ago | <p>Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.</p> | |||
| CVE-2026-28977 | medium | 6.2 | 6.2 | 19d ago | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 2… | |||
| CVE-2026-28950 | medium | 6.2 | 6.2 | 19d ago | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26… | |||
| CVE-2026-43653 | medium | 6.2 | 6.2 | 19d ago | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on … | |||
| CVE-2026-28897 | medium | 6.2 | 6.2 | 19d ago | A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 2… | |||
| CVE-2026-43666 | medium | 6.2 | 6.2 | 19d ago | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, mac… | |||
| CVE-2026-28985 | medium | 6.2 | 6.2 | 19d ago | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to … | |||
| CVE-2026-42199 | medium | 6.2 | 6.2 | 21d ago | Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior | |||
| CVE-2026-41511 | medium | 6.2 | 6.2 | 22d ago | OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle | |||
| CVE-2026-35902 | medium | 6.2 | 6.2 | 1mo ago | The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete… | |||
| CVE-2026-6386 | medium | 6.2 | 6.2 | 1mo ago | In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the pres… | |||
| CVE-2026-28833 | medium | 6.2 | 6.2 | 2mo ago | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed ap… | |||
| CVE-2026-49384 | medium | 6.1 | 6.1 | 12h ago | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible | |||
| CVE-2026-49375 | medium | 6.1 | 6.1 | 12h ago | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | |||
| CVE-2026-9646 | medium | 6.1 | 6.1 | 1d ago | A reflected cross-site scripting issue exists in URL handling. | |||
| CVE-2026-47328 | medium | 6.1 | 6.1 | 2d ago | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug… | |||
| CVE-2026-45307 | medium | 6.1 | 6.1 | 2d ago | Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urlj… | |||
| CVE-2026-7660 | medium | 6.1 | 6.1 | 2d ago | The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sani… | |||
| CVE-2026-44681 | medium | 6.1 | 6.1 | 3d ago | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authoriza… | |||
| CVE-2026-44475 | medium | 6.1 | 6.1 | 3d ago | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored va… | |||
| CVE-2026-49102 | medium | 6.1 | 6.1 | 3d ago | Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain). | |||
| CVE-2026-47119 | medium | 6.1 | 6.1 | 3d ago | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the im… | |||
| CVE-2026-3349 | medium | 6.1 | 6.1 | 3d ago | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insuffic… | |||
| CVE-2026-8906 | medium | 6.1 | 6.1 | 3d ago | The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on a function. This ma… | |||
| CVE-2026-3001 | medium | 6.1 | 6.1 | 3d ago | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output… | |||
| CVE-2026-8707 | medium | 6.1 | 6.1 | 3d ago | The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and outp… | |||
| CVE-2026-8911 | medium | 6.1 | 6.1 | 3d ago | The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on a function. This … | |||
| CVE-2026-44897 | medium | 6.1 | 6.1 | 3d ago | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTM… | |||
| CVE-2026-44708 | medium | 6.1 | 6.1 | 3d ago | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied con… | |||
| CVE-2026-44899 | medium | 6.1 | 6.1 | 3d ago | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^… | |||
| CVE-2026-44896 | medium | 6.1 | 6.1 | 3d ago | Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options direc… | |||
| CVE-2026-30894 | medium | 6.1 | 6.1 | 4d ago | Lack of output escaping leads to a XSS vector in the content history component. | |||
| CVE-2026-48903 | medium | 6.1 | 6.1 | 4d ago | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | |||
| CVE-2026-48905 | medium | 6.1 | 6.1 | 4d ago | Lack of input filtering leads to an XSS vector in the HTML filter code. | |||
| CVE-2026-25901 | medium | 6.1 | 6.1 | 4d ago | Lack of output escaping leads to a XSS vector in the multilingual associations component. | |||
| CVE-2026-25900 | medium | 6.1 | 6.1 | 4d ago | Lack of output escaping leads to a XSS vector in the feed modules. | |||
| CVE-2026-30895 | medium | 6.1 | 6.1 | 4d ago | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | |||
| CVE-2026-47070 | medium | 6.1 | 6.1 | 5d ago | HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney | |||
| CVE-2026-45249 | medium | 6.1 | 6.1 | 5d ago | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0,… | |||
| CVE-2026-36226 | medium | 6.1 | 6.1 | 8d ago | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User compone… | |||
| CVE-2026-42506 | medium | 6.1 | 6.1 | 8d ago | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | |||
| CVE-2026-42502 | medium | 6.1 | 6.1 | 8d ago | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | |||
| CVE-2026-27136 | medium | 6.1 | 6.1 | 8d ago | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | |||
| CVE-2026-25681 | medium | 6.1 | 6.1 | 8d ago | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | |||
| CVE-2026-6864 | medium | 6.1 | 6.1 | 8d ago | The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sani… | |||
| CVE-2026-3481 | medium | 6.1 | 6.1 | 8d ago | The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input saniti… | |||
| CVE-2026-22880 | medium | 6.1 | 6.1 | 9d ago | Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Ma… | |||
| CVE-2026-47099 | medium | 6.1 | 6.1 | 9d ago | TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` | |||
| CVE-2026-26028 | medium | 6.1 | 6.1 | 9d ago | CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS | |||
| CVE-2026-30691 | medium | 6.1 | 6.1 | 10d ago | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanit… | |||
| CVE-2026-5776 | medium | 6.1 | 6.1 | 10d ago | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks | |||
| CVE-2026-8627 | medium | 6.1 | 6.1 | 10d ago | The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is due to the correct_prices_pa… | |||
| CVE-2026-8626 | medium | 6.1 | 6.1 | 10d ago | The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output… | |||
| CVE-2026-8624 | medium | 6.1 | 6.1 | 10d ago | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input san… | |||
| CVE-2026-8420 | medium | 6.1 | 6.1 | 10d ago | The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a func… | |||
| CVE-2026-7462 | medium | 6.1 | 6.1 | 10d ago | The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. This is due to insufficient input sanitiz… | |||
| CVE-2026-6395 | medium | 6.1 | 6.1 | 10d ago | The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of n… | |||
| CVE-2026-6391 | medium | 6.1 | 6.1 | 10d ago | The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect no… | |||
| CVE-2026-6871 | medium | 6.1 | 6.1 | 10d ago | This module enables you to obfuscate email addresses in content. The module doesn't sufficiently sanitize user input via the Twig filter. This vulnerability is mitigated by the fact that it only af… | |||
| CVE-2026-6367 | medium | 6.1 | 6.1 | 10d ago | Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross s… | |||
| CVE-2026-6365 | medium | 6.1 | 6.1 | 10d ago | Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which which can lead to a cross-site scripting (XSS) vulnerability. | |||
| CVE-2026-6095 | medium | 6.1 | 6.1 | 10d ago | The IframeConsent element writes HTML attributes without escaping their value. This module has a XSS vulnerability. If an attacker is able to write an `<iframe-consent>` tag, they may be able to ins… | |||
| CVE-2026-5090 | medium | 6.1 | 6.1 | 10d ago | Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could… | |||
| CVE-2026-31906 | medium | 6.1 | 6.1 | 11d ago | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad… | |||
| CVE-2026-31379 | medium | 6.1 | 6.1 | 11d ago | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of… | |||
| CVE-2026-34000 | medium | 6.1 | 6.1 | 11d ago | A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an at… | |||
| CVE-2026-45243 | medium | 6.1 | 6.1 | 12d ago | Summarize contains a missing authorization vulnerability | |||
| CVE-2026-45231 | medium | 6.1 | 6.1 | 12d ago | DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san… | |||
| CVE-2026-45494 | medium | 6.1 | 6.1 | 12d ago | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |||
| CVE-2026-29965 | medium | 6.1 | 6.1 | 12d ago | HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscate… | |||
| CVE-2026-29964 | medium | 6.1 | 6.1 | 12d ago | HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaS… | |||
| CVE-2026-8656 | medium | 6.1 | 6.1 | 14d ago | Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an appli… | |||
| CVE-2026-44366 | medium | 6.1 | 6.1 | 15d ago | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Vvveb CMS com… | |||
| CVE-2026-45314 | medium | 6.1 | 6.1 | 15d ago | Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image | |||
| CVE-2026-44898 | medium | 6.1 | 6.1 | 16d ago | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used a… | |||
| CVE-2026-41932 | medium | 6.1 | 6.1 | 16d ago | Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name fiel… | |||
| CVE-2026-24710 | medium | 6.1 | 6.1 | 16d ago | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. | |||
| CVE-2026-6417 | medium | 6.1 | 6.1 | 16d ago | The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failed_orders' parameter in all versions up to, and including, 1.4.0 due to insufficient… | |||
| CVE-2026-44437 | medium | 6.1 | 6.1 | 16d ago | The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix he… | |||
| CVE-2026-44376 | medium | 6.1 | 6.1 | 16d ago | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.p… | |||
| CVE-2026-44372 | medium | 6.1 | 6.1 | 16d ago | Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after… | |||
| CVE-2026-8496 | medium | 6.1 | 6.1 | 17d ago | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated S… | |||
| CVE-2026-41255 | medium | 6.1 | 6.1 | 17d ago | CKAN has CSRF exemption primed by anonymous requests | |||
| CVE-2026-44580 | medium | 6.1 | 6.1 | 17d ago | Next.js has cross-site scripting in beforeInteractive scripts with untrusted input | |||
| CVE-2026-45028 | medium | 6.1 | 6.1 | 17d ago | Astro: Server island encrypted parameters vulnerable to cross-component replay | |||
| CVE-2026-44665 | medium | 6.1 | 6.1 | 17d ago | fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes | |||
| CVE-2026-44664 | medium | 6.1 | 6.1 | 17d ago | fast-xml-builder Comment Value regex can be bypassed | |||
| CVE-2026-44455 | medium | 6.1 | 6.1 | 17d ago | hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection | |||
| CVE-2026-44245 | medium | 6.1 | 6.1 | 17d ago | Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component | |||
| CVE-2026-42338 | medium | 6.1 | 6.1 | 17d ago | ip-address has XSS in Address6 HTML-emitting methods |