Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85586 | UNKNOWN | — | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA … | Sep 04, 2026 |
| CVE-2026-85585 | HIGH | 7.5 | SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated … | Sep 04, 2026 |
| CVE-2026-85584 | HIGH | 7.5 | SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing … | Sep 04, 2026 |
| CVE-2026-85583 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader … | Sep 04, 2026 |
| CVE-2026-85582 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can … | Sep 04, 2026 |
| CVE-2026-85581 | HIGH | 7.5 | SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or … | Sep 04, 2026 |
| CVE-2026-85580 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read … | Sep 04, 2026 |
| CVE-2026-85579 | MEDIUM | 4.3 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs … | Sep 04, 2026 |
| CVE-2026-85578 | MEDIUM | 6.5 | SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers … | Sep 04, 2026 |
| CVE-2026-85577 | MEDIUM | 5.4 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag … | Sep 04, 2026 |
| CVE-2026-19080 | HIGH | 7.5 | Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. | Sep 04, 2026 |
| CVE-2026-19051 | HIGH | 7.1 | Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448. | Sep 04, 2026 |
| CVE-2026-19043 | MEDIUM | 4.3 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448. | Sep 04, 2026 |
| CVE-2026-18957 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: … | Sep 04, 2026 |
| CVE-2026-85534 | MEDIUM | 5.9 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data … | Sep 04, 2026 |
| CVE-2026-85512 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation … | Sep 04, 2026 |
| CVE-2026-84428 | HIGH | 7.5 | fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the … | Sep 04, 2026 |
| CVE-2026-84045 | MEDIUM | 5.3 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before … | Sep 04, 2026 |
| CVE-2026-79707 | UNKNOWN | — | A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote … | Sep 04, 2026 |
| CVE-2026-4644 | UNKNOWN | — | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to … | Sep 04, 2026 |
| CVE-2026-27347 | MEDIUM | 5.3 | Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2. | Sep 04, 2026 |
| CVE-2026-85547 | UNKNOWN | — | A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified … | Sep 04, 2026 |
| CVE-2026-85546 | UNKNOWN | — | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, … | Sep 04, 2026 |
| CVE-2026-85541 | MEDIUM | 5.4 | DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website. | Sep 04, 2026 |
| CVE-2026-85540 | HIGH | 8.8 | DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | Sep 04, 2026 |