Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5695 | UNKNOWN | — | Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without … | Sep 23, 2026 |
| CVE-2026-96454 | HIGH | 8.2 | Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they … | Sep 23, 2026 |
| CVE-2026-96443 | MEDIUM | 6.5 | Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE. | Sep 23, 2026 |
| CVE-2026-95627 | HIGH | 7.7 | When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be … | Sep 23, 2026 |
| CVE-2026-95626 | HIGH | 8.3 | Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in … | Sep 23, 2026 |
| CVE-2026-94251 | MEDIUM | 6.5 | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. … | Sep 23, 2026 |
| CVE-2026-94243 | HIGH | 7.3 | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to … | Sep 23, 2026 |
| CVE-2026-92001 | MEDIUM | 6.1 | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users … | Sep 23, 2026 |
| CVE-2026-91999 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are … | Sep 23, 2026 |
| CVE-2026-91928 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are … | Sep 23, 2026 |
| CVE-2026-91852 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are … | Sep 23, 2026 |
| CVE-2026-79616 | UNKNOWN | — | Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. | Sep 23, 2026 |
| CVE-2026-73192 | MEDIUM | 6.1 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior … | Sep 23, 2026 |
| CVE-2026-95625 | MEDIUM | 5.9 | The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains … | Sep 23, 2026 |
| CVE-2026-93368 | HIGH | 7.5 | The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, … | Sep 23, 2026 |
| CVE-2026-42801 | HIGH | 7.4 | NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c. | Sep 23, 2026 |
| CVE-2026-31377 | HIGH | 7.5 | An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected … | Sep 23, 2026 |
| CVE-2026-15027 | HIGH | 8.8 | CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary … | Sep 23, 2026 |
| CVE-2026-92378 | UNKNOWN | — | A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency … | Sep 23, 2026 |
| CVE-2026-91818 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, … | Sep 23, 2026 |
| CVE-2026-91817 | MEDIUM | 6.1 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause … | Sep 23, 2026 |
| CVE-2026-91816 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access … | Sep 23, 2026 |
| CVE-2026-91815 | HIGH | 7.8 | Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap … | Sep 23, 2026 |
| CVE-2026-91814 | MEDIUM | 5.3 | A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing … | Sep 23, 2026 |
| CVE-2026-91813 | HIGH | 8.8 | A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking … | Sep 23, 2026 |