Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55204
Total
4355
Critical
16406
High
16086
Medium
CVE ID Severity Score Description Published
CVE-2026-87070 MEDIUM 5.3 The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the … Sep 23, 2026
CVE-2026-86612 MEDIUM 5.6 The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to … Sep 23, 2026
CVE-2026-86604 MEDIUM 4.8 The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expanding them which, in a non-default configuration, allows … Sep 23, 2026
CVE-2026-86601 MEDIUM 6.5 The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing … Sep 23, 2026
CVE-2026-5696 UNKNOWN — Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows … Sep 23, 2026
CVE-2026-5695 UNKNOWN — Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without … Sep 23, 2026
CVE-2026-96454 HIGH 8.2 Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they … Sep 23, 2026
CVE-2026-96443 MEDIUM 6.5 Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE. Sep 23, 2026
CVE-2026-95627 HIGH 7.7 When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be … Sep 23, 2026
CVE-2026-95626 HIGH 8.3 Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in … Sep 23, 2026
CVE-2026-94251 MEDIUM 6.5 A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. … Sep 23, 2026
CVE-2026-94243 HIGH 7.3 A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to … Sep 23, 2026
CVE-2026-92001 MEDIUM 6.1 Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users … Sep 23, 2026
CVE-2026-91999 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are … Sep 23, 2026
CVE-2026-91928 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are … Sep 23, 2026
CVE-2026-91852 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are … Sep 23, 2026
CVE-2026-79616 UNKNOWN — Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. Sep 23, 2026
CVE-2026-73192 MEDIUM 6.1 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior … Sep 23, 2026
CVE-2026-95625 MEDIUM 5.9 The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains … Sep 23, 2026
CVE-2026-93368 HIGH 7.5 The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, … Sep 23, 2026
CVE-2026-42801 HIGH 7.4 NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c. Sep 23, 2026
CVE-2026-31377 HIGH 7.5 An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected … Sep 23, 2026
CVE-2026-15027 HIGH 8.8 CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary … Sep 23, 2026
CVE-2026-92378 UNKNOWN — A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency … Sep 23, 2026
CVE-2026-91818 HIGH 7.8 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, … Sep 23, 2026