CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 28d ago | 6.1 | DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected. |
| Exploit 28d ago | 6.1 | DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy. |
| Exploit 28d ago | 5.3 | A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
| Exploit 28d ago | 5.3 | A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. |
| Exploit 28d ago | 6.5 | SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the file without the IsSubPath or IsSensitivePath checks added in the earlier export-disclosure hardening (GHSA-6865-qjcf-286f). An authenticated attacker can send percent-encoded traversal sequences (e.g. /export/temp/%2e%2e/.../etc/passwd, where %2e%2e is decoded to '..') to read arbitrary files outside TempDir, including /etc/passwd, SSH keys (~/.ssh/*), and SiYuan workspace *.db and *.log files, bypassing the sensitive-file protection. |
| 28d ago | 5.9 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
| 28d ago | 5.9 | Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. |
| 28d ago | 4.3 | Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |
| 28d ago | 6.5 | Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. |
| 28d ago | 4.3 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. |
| 28d ago | 5.9 | Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. |
| 28d ago | 4.8 | Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. |
| 28d ago | 4.3 | Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. |
| 28d ago | 5.3 | Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. |
| 28d ago | 5.3 | Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. |
| 28d ago | 4.3 | Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. |
| 28d ago | 5.3 | Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. |
| 28d ago | 6.5 | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. |
| 28d ago | 5.4 | Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4. |
| 28d ago | 5.3 | Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. |
| 28d ago | 5.3 | Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| 28d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| 28d ago | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. |
| 28d ago | 6.5 | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. |