Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45002
Total
3609
Critical
13358
High
13243
Medium
CVE ID Severity Score Description Published
CVE-2026-76210 MEDIUM 6.5 phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ … Aug 19, 2026
CVE-2026-76209 MEDIUM 4.3 phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can … Aug 19, 2026
CVE-2026-76208 HIGH 8.2 phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls … Aug 19, 2026
CVE-2026-76207 HIGH 8.1 phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a … Aug 19, 2026
CVE-2026-76206 MEDIUM 5.3 phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing unauthenticated attackers to retrieve draft FAQ metadata. Attackers can access … Aug 19, 2026
CVE-2026-76205 HIGH 8.1 phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in … Aug 19, 2026
CVE-2026-75920 MEDIUM 5.3 phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race … Aug 19, 2026
CVE-2026-75919 MEDIUM 5.3 phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode … Aug 19, 2026
CVE-2026-75918 HIGH 8.8 phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file … Aug 19, 2026
CVE-2026-75917 HIGH 8.6 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document … Aug 19, 2026
CVE-2026-75916 HIGH 8.6 SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo … Aug 19, 2026
CVE-2026-75148 MEDIUM 6.1 cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_validate() that allows remote attackers to cause memory disclosure and … Aug 19, 2026
CVE-2026-75114 UNKNOWN Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no … Aug 19, 2026
CVE-2026-74804 UNKNOWN Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as … Aug 19, 2026
CVE-2026-74803 UNKNOWN Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls … Aug 19, 2026
CVE-2026-71694 UNKNOWN An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return … Aug 19, 2026
CVE-2026-70424 MEDIUM 6.5 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker … Aug 19, 2026
CVE-2026-70423 MEDIUM 6.5 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could … Aug 19, 2026
CVE-2026-70422 HIGH 8.1 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged … Aug 19, 2026
CVE-2026-70421 HIGH 7.2 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, … Aug 19, 2026
CVE-2026-65612 UNKNOWN nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside … Aug 19, 2026
CVE-2026-65611 UNKNOWN nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive whose … Aug 19, 2026
CVE-2026-65610 UNKNOWN nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can … Aug 19, 2026
CVE-2026-65609 UNKNOWN nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file … Aug 19, 2026
CVE-2026-56088 HIGH 7.1 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged … Aug 19, 2026