Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

53238
Total
4231
Critical
15843
High
15500
Medium
CVE ID Severity Score Description Published
CVE-2026-12595 HIGH 8.1 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability … Jul 10, 2026
CVE-2026-59858 HIGH 7.8 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field … Jul 09, 2026
CVE-2026-59857 MEDIUM 5.5 Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell … Jul 09, 2026
CVE-2026-59856 HIGH 7.8 Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken … Jul 09, 2026
CVE-2026-59855 UNKNOWN — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing … Jul 09, 2026
CVE-2026-59854 MEDIUM 4.9 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose … Jul 09, 2026
CVE-2026-59853 MEDIUM 6.5 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used … Jul 09, 2026
CVE-2026-59834 HIGH 7.5 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used … Jul 09, 2026
CVE-2026-59833 UNKNOWN — SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization … Jul 09, 2026
CVE-2026-59832 HIGH 7.7 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the … Jul 09, 2026
CVE-2026-59831 MEDIUM 4.4 GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command … Jul 09, 2026
CVE-2026-57501 NONE — Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load … Jul 09, 2026
CVE-2026-44342 MEDIUM 5.3 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding … Jul 09, 2026
CVE-2026-33655 HIGH 7.7 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did … Jul 09, 2026
CVE-2026-59828 MEDIUM 5.3 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked … Jul 09, 2026
CVE-2026-58144 MEDIUM 5.4 Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbitrary script payloads by supplying … Jul 09, 2026
CVE-2026-58143 HIGH 8.8 Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into … Jul 09, 2026
CVE-2026-58123 CRITICAL 9.8 Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal … Jul 09, 2026
CVE-2026-58122 CRITICAL 9.1 Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a … Jul 09, 2026
CVE-2026-57054 MEDIUM 5.8 A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based … Jul 09, 2026
CVE-2026-57032 MEDIUM 6.5 An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated … Jul 09, 2026
CVE-2026-57031 MEDIUM 4.7 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent … Jul 09, 2026
CVE-2026-57030 MEDIUM 5.9 A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX … Jul 09, 2026
CVE-2026-57029 MEDIUM 5.3 A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause … Jul 09, 2026
CVE-2026-57028 HIGH 7.3 An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. … Jul 09, 2026