Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-62382 | UNKNOWN | — | PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously … | Aug 22, 2026 |
| CVE-2026-62381 | MEDIUM | 6.6 | luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For … | Aug 22, 2026 |
| CVE-2026-62380 | UNKNOWN | — | Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) … | Aug 22, 2026 |
| CVE-2026-62243 | HIGH | 7.5 | Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager … | Aug 22, 2026 |
| CVE-2026-62204 | MEDIUM | 6.6 | SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing … | Aug 22, 2026 |
| CVE-2026-60084 | HIGH | 8.7 | SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated … | Aug 22, 2026 |
| CVE-2026-60083 | MEDIUM | 4.9 | SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by … | Aug 22, 2026 |
| CVE-2026-59809 | MEDIUM | 4.9 | SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client … | Aug 22, 2026 |
| CVE-2026-59808 | HIGH | 8.8 | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts … | Aug 22, 2026 |
| CVE-2026-59256 | HIGH | 7.5 | WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid … | Aug 22, 2026 |
| CVE-2026-58003 | HIGH | 7.1 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can … | Aug 22, 2026 |
| CVE-2026-58002 | MEDIUM | 6.5 | WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by … | Aug 22, 2026 |
| CVE-2026-58001 | MEDIUM | 5.7 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store … | Aug 22, 2026 |
| CVE-2026-57998 | HIGH | 7.8 | better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without … | Aug 22, 2026 |
| CVE-2026-57944 | MEDIUM | 5.4 | AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to … | Aug 22, 2026 |
| CVE-2026-56380 | MEDIUM | 5.3 | AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public … | Aug 22, 2026 |
| CVE-2026-4244 | MEDIUM | 4.3 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all … | Aug 22, 2026 |
| CVE-2026-11948 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 22, 2026 |
| CVE-2026-11947 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 22, 2026 |
| CVE-2026-77988 | MEDIUM | 6.6 | A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command … | Aug 22, 2026 |
| CVE-2026-66917 | UNKNOWN | — | Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS … | Aug 22, 2026 |
| CVE-2026-66916 | UNKNOWN | — | Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON … | Aug 22, 2026 |
| CVE-2026-4245 | MEDIUM | 4.3 | The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` … | Aug 22, 2026 |
| CVE-2026-3424 | MEDIUM | 5.3 | The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up … | Aug 22, 2026 |
| CVE-2026-77946 | CRITICAL | 10.0 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone … | Aug 22, 2026 |