Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-84115 — Cleo Harmony JWT Refresh Token connections privileges management

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulatio…

harmony | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-84114 — Cleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions improper authent…

A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertions of the component SAML Authentication. Such manipulation of the argument…

harmony | Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-84111 — Chanjet CRM jxf_dump_table.php sql injection

A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of the file jxf_dump_table.php. This manipulation of the argument gblOrgID causes sql injection. Remote…

chanjet_crm crm | Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.5 MEDIUM
CVE-2026-84110 — Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-sid…

A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement o…

releasit_cod_form_upsells | Remote | Authentication
Sep 01, 2026 Sep 04, 2026
Sep 01, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-83619 — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names …

xmldom | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83618 — xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embed…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publi…

xmldom | Remote | Injection
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83617 — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use t…

xmldom | Remote | Injection
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83616 — xmldom: Processing Instruction Target Injection Bypasses requireWellFormed

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | XML External Entity
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83615 — xmldom: Quadratic-memory consumption

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.…

xmldom | Remote | XML External Entity
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83614 — xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStart…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.3.0 through 0.6.…

xmldom | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83613 — xmldom: Quadratic-time attribute deduplication

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83612 — xmldom: HTML raw-text closing-tag case mismatch causes output amplification

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishand…

xmldom | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.9 MEDIUM
CVE-2026-83611 — xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a lin…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | XML External Entity
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-83610 — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFor…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | XML External Entity
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83609 — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line termin…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QNa…

xmldom | Remote | Injection
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83608 — xmldom: DocType `name` Injection Bypasses requireWellFormed

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | XML External Entity
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83607 — xmldom: Element name injection via createElement() bypasses requireWellFormed

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | Cross-Site Scripting
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83606 — xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instruct…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets …

xmldom | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-83605 — xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, …

xmldom | Remote | XML External Entity
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
5.6 MEDIUM
CVE-2026-83557 — jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsaf…

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resoluti…

jackson-databind | Remote | Path Traversal
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
Showing 20 of 15023 Results