Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12595 | HIGH | 8.1 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability … | Jul 10, 2026 |
| CVE-2026-59858 | HIGH | 7.8 | Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field … | Jul 09, 2026 |
| CVE-2026-59857 | MEDIUM | 5.5 | Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell … | Jul 09, 2026 |
| CVE-2026-59856 | HIGH | 7.8 | Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken … | Jul 09, 2026 |
| CVE-2026-59855 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing … | Jul 09, 2026 |
| CVE-2026-59854 | MEDIUM | 4.9 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose … | Jul 09, 2026 |
| CVE-2026-59853 | MEDIUM | 6.5 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used … | Jul 09, 2026 |
| CVE-2026-59834 | HIGH | 7.5 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used … | Jul 09, 2026 |
| CVE-2026-59833 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization … | Jul 09, 2026 |
| CVE-2026-59832 | HIGH | 7.7 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the … | Jul 09, 2026 |
| CVE-2026-59831 | MEDIUM | 4.4 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command … | Jul 09, 2026 |
| CVE-2026-57501 | NONE | — | Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load … | Jul 09, 2026 |
| CVE-2026-44342 | MEDIUM | 5.3 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding … | Jul 09, 2026 |
| CVE-2026-33655 | HIGH | 7.7 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did … | Jul 09, 2026 |
| CVE-2026-59828 | MEDIUM | 5.3 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked … | Jul 09, 2026 |
| CVE-2026-58144 | MEDIUM | 5.4 | Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbitrary script payloads by supplying … | Jul 09, 2026 |
| CVE-2026-58143 | HIGH | 8.8 | Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into … | Jul 09, 2026 |
| CVE-2026-58123 | CRITICAL | 9.8 | Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal … | Jul 09, 2026 |
| CVE-2026-58122 | CRITICAL | 9.1 | Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a … | Jul 09, 2026 |
| CVE-2026-57054 | MEDIUM | 5.8 | A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based … | Jul 09, 2026 |
| CVE-2026-57032 | MEDIUM | 6.5 | An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated … | Jul 09, 2026 |
| CVE-2026-57031 | MEDIUM | 4.7 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent … | Jul 09, 2026 |
| CVE-2026-57030 | MEDIUM | 5.9 | A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX … | Jul 09, 2026 |
| CVE-2026-57029 | MEDIUM | 5.3 | A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause … | Jul 09, 2026 |
| CVE-2026-57028 | HIGH | 7.3 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. … | Jul 09, 2026 |