Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41921
Total
3420
Critical
12394
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85592 | LOW | 3.7 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is … | Sep 04, 2026 |
| CVE-2026-85591 | UNKNOWN | — | phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without … | Sep 04, 2026 |
| CVE-2026-85590 | UNKNOWN | — | phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that … | Sep 04, 2026 |
| CVE-2026-85589 | UNKNOWN | — | phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any … | Sep 04, 2026 |
| CVE-2026-85588 | UNKNOWN | — | phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP … | Sep 04, 2026 |
| CVE-2026-85587 | UNKNOWN | — | phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions … | Sep 04, 2026 |
| CVE-2026-85586 | UNKNOWN | — | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA … | Sep 04, 2026 |
| CVE-2026-85585 | HIGH | 7.5 | SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated … | Sep 04, 2026 |
| CVE-2026-85584 | HIGH | 7.5 | SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing … | Sep 04, 2026 |
| CVE-2026-85583 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader … | Sep 04, 2026 |
| CVE-2026-85582 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can … | Sep 04, 2026 |
| CVE-2026-85581 | HIGH | 7.5 | SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or … | Sep 04, 2026 |
| CVE-2026-85580 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read … | Sep 04, 2026 |
| CVE-2026-85579 | MEDIUM | 4.3 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs … | Sep 04, 2026 |
| CVE-2026-85578 | MEDIUM | 6.5 | SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers … | Sep 04, 2026 |
| CVE-2026-85577 | MEDIUM | 5.4 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag … | Sep 04, 2026 |
| CVE-2026-19080 | HIGH | 7.5 | Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. | Sep 04, 2026 |
| CVE-2026-19051 | HIGH | 7.1 | Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448. | Sep 04, 2026 |
| CVE-2026-19043 | MEDIUM | 4.3 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448. | Sep 04, 2026 |
| CVE-2026-18957 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: … | Sep 04, 2026 |
| CVE-2026-85534 | MEDIUM | 5.9 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data … | Sep 04, 2026 |
| CVE-2026-85512 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation … | Sep 04, 2026 |
| CVE-2026-84428 | HIGH | 7.5 | fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the … | Sep 04, 2026 |
| CVE-2026-84045 | MEDIUM | 5.3 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before … | Sep 04, 2026 |
| CVE-2026-79707 | UNKNOWN | — | A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote … | Sep 04, 2026 |