Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-78142 — code-projects Barangay Resident Profiling Management System Restore/Delete archived_recor…

A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The m…

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.4 HIGH
CVE-2026-78141 — Tenda CH22 exeCommand formexeCommand command injection

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. Th…

ch22 | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-78143 — code-projects Barangay Resident Profiling Management System Resident Search Functionality…

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functiona…

| Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-78183 — DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for …

| Memory Corruption
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.8 MEDIUM
CVE-2026-78140 — Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special el…

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the compo…

Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session auth…

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds …

| Authentication
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-75922 — Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-d…

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application perce…

| Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-9769 — justhtml before 1.10.0 Denial of Service via deeply nested HTML

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_sel…

Remote | Denial of Service
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-8630 — justhtml before 1.12.0 Mutation XSS via Raw Text Elements

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is pr…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-8445 — justhtml before 1.12.0 Sanitizer Bypass via Markdown

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). Wh…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-7808 — justhtml before 1.16.0 Multiple Security Issues via Sanitization

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scr…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-77088 — justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject …

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-74793 — justhtml before 3.11.0 XSS via selectedcontent projection

justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elem…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-6827 — justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous conten…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-5751 — justhtml before 1.14.0 Mutation XSS via custom sanitization policies

justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g.,…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-5389 — justhtml before 1.13.0 XSS via code fence breakout

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanit…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-5388 — justhtml before 1.15.0 Multiple Security Issues

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and se…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-4671 — justhtml before 1.18.0 Denial of Service via CSS Selector

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query()…

Remote | Denial of Service
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.9 CRITICAL
CVE-2026-78155 — Untrusted Search Path in StackGres

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.5 MEDIUM
CVE-2026-78115 — SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.ph…

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. …

class_and_exam_timetabling_system | Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
Showing 20 of 11456 Results