Known Vulnerabilities for Expression Web by Microsoft
Listed below are 8 of the newest known vulnerabilities associated with "Expression Web" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-106454 json | Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegex... | Not Provided | 2026-10-06 | 2026-10-07 |
| CVE-2026-105219 json | Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in li... | Not Provided | 2026-10-04 | 2026-10-05 |
| CVE-2026-104861 json | probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/par... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-104711 json | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulner... | Not Provided | 2026-10-05 | 2026-10-06 |
| CVE-2026-103923 json | KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordin... | Not Provided | 2026-10-01 | 2026-10-06 |
| CVE-2026-103913 json | The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listi... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-103111 json | PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bound... | Not Provided | 2026-09-30 | 2026-10-03 |
| CVE-2026-103043 json | anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-102990 json | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-102830 json | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architectur... | Not Provided | 2026-09-29 | 2026-09-29 |