Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-85586 UNKNOWN phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA … Sep 04, 2026
CVE-2026-85585 HIGH 7.5 SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated … Sep 04, 2026
CVE-2026-85584 HIGH 7.5 SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing … Sep 04, 2026
CVE-2026-85583 MEDIUM 6.5 SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader … Sep 04, 2026
CVE-2026-85582 MEDIUM 6.5 SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can … Sep 04, 2026
CVE-2026-85581 HIGH 7.5 SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or … Sep 04, 2026
CVE-2026-85580 MEDIUM 6.5 SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read … Sep 04, 2026
CVE-2026-85579 MEDIUM 4.3 SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs … Sep 04, 2026
CVE-2026-85578 MEDIUM 6.5 SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers … Sep 04, 2026
CVE-2026-85577 MEDIUM 5.4 AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag … Sep 04, 2026
CVE-2026-19080 HIGH 7.5 Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. Sep 04, 2026
CVE-2026-19051 HIGH 7.1 Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448. Sep 04, 2026
CVE-2026-19043 MEDIUM 4.3 Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448. Sep 04, 2026
CVE-2026-18957 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: … Sep 04, 2026
CVE-2026-85534 MEDIUM 5.9 A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data … Sep 04, 2026
CVE-2026-85512 HIGH 7.3 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation … Sep 04, 2026
CVE-2026-84428 HIGH 7.5 fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the … Sep 04, 2026
CVE-2026-84045 MEDIUM 5.3 The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before … Sep 04, 2026
CVE-2026-79707 UNKNOWN A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote … Sep 04, 2026
CVE-2026-4644 UNKNOWN A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to … Sep 04, 2026
CVE-2026-27347 MEDIUM 5.3 Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2. Sep 04, 2026
CVE-2026-85547 UNKNOWN A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified … Sep 04, 2026
CVE-2026-85546 UNKNOWN MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, … Sep 04, 2026
CVE-2026-85541 MEDIUM 5.4 DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website. Sep 04, 2026
CVE-2026-85540 HIGH 8.8 DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. Sep 04, 2026