Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41921
Total
3420
Critical
12394
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-85592 LOW 3.7 phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is … Sep 04, 2026
CVE-2026-85591 UNKNOWN phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without … Sep 04, 2026
CVE-2026-85590 UNKNOWN phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that … Sep 04, 2026
CVE-2026-85589 UNKNOWN phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any … Sep 04, 2026
CVE-2026-85588 UNKNOWN phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP … Sep 04, 2026
CVE-2026-85587 UNKNOWN phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions … Sep 04, 2026
CVE-2026-85586 UNKNOWN phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA … Sep 04, 2026
CVE-2026-85585 HIGH 7.5 SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated … Sep 04, 2026
CVE-2026-85584 HIGH 7.5 SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing … Sep 04, 2026
CVE-2026-85583 MEDIUM 6.5 SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader … Sep 04, 2026
CVE-2026-85582 MEDIUM 6.5 SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can … Sep 04, 2026
CVE-2026-85581 HIGH 7.5 SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or … Sep 04, 2026
CVE-2026-85580 MEDIUM 6.5 SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read … Sep 04, 2026
CVE-2026-85579 MEDIUM 4.3 SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs … Sep 04, 2026
CVE-2026-85578 MEDIUM 6.5 SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers … Sep 04, 2026
CVE-2026-85577 MEDIUM 5.4 AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag … Sep 04, 2026
CVE-2026-19080 HIGH 7.5 Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. Sep 04, 2026
CVE-2026-19051 HIGH 7.1 Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448. Sep 04, 2026
CVE-2026-19043 MEDIUM 4.3 Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448. Sep 04, 2026
CVE-2026-18957 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: … Sep 04, 2026
CVE-2026-85534 MEDIUM 5.9 A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data … Sep 04, 2026
CVE-2026-85512 HIGH 7.3 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation … Sep 04, 2026
CVE-2026-84428 HIGH 7.5 fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the … Sep 04, 2026
CVE-2026-84045 MEDIUM 5.3 The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before … Sep 04, 2026
CVE-2026-79707 UNKNOWN A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote … Sep 04, 2026