Known Vulnerabilities for Expression Web by Microsoft
Listed below are 8 of the newest known vulnerabilities associated with "Expression Web" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44643 json | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-42811 json | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a c... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-41901 json | Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypas... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-41883 json | OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-41705 json | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized docu... | Not Provided | 2026-05-09 | 2026-05-11 |
| CVE-2026-41645 json | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerabili... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-41422 json | Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and gro... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-41285 json | In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discover... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-41282 json | ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step template... | Not Provided | 2026-04-20 | 2026-04-21 |
| CVE-2026-41139 json | Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary Java... | Not Provided | 2026-05-07 | 2026-05-07 |