Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44727
Total
3597
Critical
13286
High
13138
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74793 | MEDIUM | 6.1 | justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML … | Aug 23, 2026 |
| CVE-2026-6827 | MEDIUM | 6.1 | justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as … | Aug 23, 2026 |
| CVE-2026-5751 | MEDIUM | 6.1 | justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespaces=False … | Aug 23, 2026 |
| CVE-2026-5389 | MEDIUM | 6.1 | justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre … | Aug 23, 2026 |
| CVE-2026-5388 | CRITICAL | 9.8 | justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on … | Aug 23, 2026 |
| CVE-2026-4671 | HIGH | 7.5 | justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based … | Aug 23, 2026 |
| CVE-2026-78155 | CRITICAL | 9.9 | privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges | Aug 23, 2026 |
| CVE-2026-78115 | MEDIUM | 5.4 | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component … | Aug 23, 2026 |
| CVE-2026-78112 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation … | Aug 23, 2026 |
| CVE-2026-10053 | HIGH | 8.5 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 23, 2026 |
| CVE-2026-77116 | MEDIUM | 4.3 | Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough … | Aug 23, 2026 |
| CVE-2026-77115 | HIGH | 7.1 | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | Aug 23, 2026 |
| CVE-2026-77003 | LOW | 2.7 | The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role … | Aug 23, 2026 |
| CVE-2026-14853 | MEDIUM | 4.3 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be … | Aug 23, 2026 |
| CVE-2026-13598 | UNKNOWN | — | The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account … | Aug 23, 2026 |
| CVE-2026-78063 | HIGH | 7.4 | A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the … | Aug 23, 2026 |
| CVE-2026-78062 | HIGH | 7.3 | A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT … | Aug 23, 2026 |
| CVE-2026-78061 | MEDIUM | 6.3 | A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing … | Aug 23, 2026 |
| CVE-2026-78060 | MEDIUM | 4.3 | A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the … | Aug 23, 2026 |
| CVE-2026-78059 | MEDIUM | 4.3 | A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument … | Aug 23, 2026 |
| CVE-2026-78057 | MEDIUM | 6.3 | A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of … | Aug 23, 2026 |
| CVE-2026-78056 | MEDIUM | 6.3 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. The manipulation of … | Aug 23, 2026 |
| CVE-2026-78055 | MEDIUM | 4.3 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file … | Aug 23, 2026 |
| CVE-2026-78136 | HIGH | 7.8 | chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py. | Aug 23, 2026 |
| CVE-2026-78054 | MEDIUM | 4.3 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation … | Aug 23, 2026 |