CURE53
16 CVEs tracked since 2026. Since Jul 2026, none of them reached CISA KEV.
CURE53 CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-07 | 16 | 0 |
Products
The products that kept showing up in CURE53's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting CURE53.
- CVE-2026-75838DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook—
- CVE-2026-66010DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING6.1
- CVE-2026-65913DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES6.1
- CVE-2026-65914DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization6.1
- CVE-2026-65912DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR6.1
- CVE-2026-65911DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage6.1
- CVE-2026-65904DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode4.7
- CVE-2026-65903DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS6.1
- CVE-2026-65902DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags6.1
- CVE-2026-65901DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName6.1
- CVE-2026-65900DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM6.1
- CVE-2026-65899DOMPurify before 3.4.9 Trusted Types Policy State Contamination6.1
- CVE-2026-65898DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig7.2
- CVE-2026-49978DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content6.1
- CVE-2026-49459DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM6.1
The record
- Peak rank
- #82 in Jul 2026
- Busiest month shown
- Jul 2026, 16 CVEs
- Months with a KEV entry
- 0 since Jul 2026
- Monthly snapshots
- 1 since 2026