VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15598 CVEsRSS

CVE-2026-87071Medium· 5.3
5d ago

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public f…

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public f…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-86612Medium· 5.6
5d ago

The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a pub…

The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a pub…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-90950Medium· 5.3
5d ago

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the…

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-87978Medium· 5.3
5d ago

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.

▾ SunlitEPSS 0.11%via NVD
CVE-2026-86601Medium· 6.5
5d ago

The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed serv…

The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed serv…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-96454High· 8.2
5d ago

Pake turns a website into a desktop application built on Tauri

Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrusted web content. The first is in src…

▾ Twilighttw93 · pake-cliEPSS 0.34%via NVD
CVE-2026-96443Medium· 6.5
5d ago

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

▾ SunlitApache Software Foundation · Apache DorisEPSS 0.34%via NVD
CVE-2026-95627High· 7.7
5d ago

When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single use…

When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single use…

▾ TwilightTauri · tauri-plugin-dialogEPSS 0.20%via NVD
CVE-2026-95626High· 8.3
5d ago

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, th…

▾ TwilightTauri · tauriEPSS 0.28%via NVD
CVE-2026-94251Medium· 6.5
5d ago

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version…

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version…

▾ SunlitApache Software Foundation · Apache Sling Security BundleEPSS 0.19%via NVD
CVE-2026-94243High· 7.3
5d ago

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes t…

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes t…

▾ TwilightApache Software Foundation · Apache Sling Security BundleEPSS 0.13%via NVD
CVE-2026-92001Medium· 6.1
5d ago

Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-91999Medium· 6.1
5d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-91928Medium· 6.1
5d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-91852Medium· 6.1
5d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.21%via NVD
CVE-2026-79616Low· 0.6⚖ disputed
5d ago

Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.

Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.

▾ Sunlitqt · qtEPSS 0.10%via NVD
CVE-2026-73192Medium· 6.1
5d ago

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected…

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-95625Medium· 5.9
5d ago

The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes

The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS…

▾ SunlitTauri · tauri-plugin-updaterEPSS 0.16%via NVD
CVE-2026-93368High· 7.5
5d ago

The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied para…

The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied para…

▾ Twilighttravispluse · Rename wp-login.php to anything you wantEPSS 0.30%via NVD
CVE-2026-42801High· 7.4
5d ago

NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.

NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.

▾ TwilightASR · Crane,FalconEPSS 0.21%via NVD
CVE-2026-31377High· 7.5
5d ago

An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node inf…

An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node inf…

▾ TwilightApache Software Foundation · Apache DorisEPSS 0.54%via NVD
CVE-2026-15027High· 8.8
5d ago

CGServiSign developed by Changing has a OS Command Injection vulnerability

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting…

▾ TwilightChanging · CGServiSignEPSS 3.2%via NVD
CVE-2026-92378Medium· 4.1
5d ago

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retain…

▾ SunlitNT-ware · uniFLOW OnlineEPSS 0.12%via NVD
CVE-2026-91818High· 7.8
5d ago

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently access…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.12%via NVD
CVE-2026-91817Medium· 6.1
5d ago

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-…

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.11%via NVD
CVE-2026-91816High· 7.8
5d ago

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been rel…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.12%via NVD
CVE-2026-91815High· 7.8
5d ago

Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introduc…

Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introduc…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.13%via NVD
CVE-2026-91814Medium· 5.3
5d ago

A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents

A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed c…

▾ SunlitFoxit Software Inc. · Foxit PDF EditorEPSS 0.11%via NVD
CVE-2026-91813High· 8.8
5d ago

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attac…

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.09%via NVD
CVE-2026-91812High· 7.9
5d ago

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.

▾ TwilightFoxit Software Inc. · Foxit PDF EditorEPSS 0.08%via NVD
CVEs tagged “cve.org” — page 70 · VulnSea