Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-5696 — Multiple vulnerabilities in the Microweber administration panel

Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attac…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.4 HIGH
CVE-2026-5695 — Multiple vulnerabilities in the Microweber administration panel

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit t…

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-96454 — Pake grants unrestricted IPC access to every HTTPS origin loaded in generated applications

Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrust…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-96443 — Apache Doris: JDBC driver URL validation bypass leads to remote code execution

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

doris | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.7 HIGH
CVE-2026-95627 — Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controll…

When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an en…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.3 HIGH
CVE-2026-95626 — Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XS…

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive.…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-94251 — Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shap…

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-94243 — Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to u…

| Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-92001 — Apache Sling XSS: Missing parser resource limits

Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended…

| XML External Entity
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-91999 — Apache Sling XSS: Improper escaping in the XSS Webconsole plugin

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended…

| Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-91928 — Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prot…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended…

| Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-91852 — Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended…

| Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.6 LOW
CVE-2026-79616 — Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt…

Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.

| Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-73192 — Apache Sling XSS: XSS possible through XSSAPI.getValidHref()

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may al…

| Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-90950 — Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users …

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87978 — Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscript…

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce …

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87848 — MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure

The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87071 — Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthen…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87070 — Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing

The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it…

| Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86612 — Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Da…

The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have …

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14295 Results