Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19924 | CRITICAL | 9.8 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper … | Aug 16, 2026 |
| CVE-2026-19923 | MEDIUM | 6.3 | A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the … | Aug 16, 2026 |
| CVE-2026-19922 | LOW | 3.5 | A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing … | Aug 16, 2026 |
| CVE-2026-19921 | MEDIUM | 6.3 | A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of … | Aug 16, 2026 |
| CVE-2026-19920 | MEDIUM | 6.3 | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId … | Aug 16, 2026 |
| CVE-2026-19919 | HIGH | 7.3 | A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation … | Aug 16, 2026 |
| CVE-2026-19918 | MEDIUM | 6.3 | A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation … | Aug 16, 2026 |
| CVE-2026-19917 | MEDIUM | 6.3 | A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a … | Aug 15, 2026 |
| CVE-2026-74767 | UNKNOWN | — | Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed … | Aug 15, 2026 |
| CVE-2026-74764 | UNKNOWN | — | Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly … | Aug 15, 2026 |
| CVE-2026-73055 | MEDIUM | 4.8 | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly … | Aug 15, 2026 |
| CVE-2026-73054 | HIGH | 7.5 | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session … | Aug 15, 2026 |
| CVE-2026-73053 | CRITICAL | 9.0 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons … | Aug 15, 2026 |
| CVE-2026-73052 | CRITICAL | 9.0 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can … | Aug 15, 2026 |
| CVE-2026-73050 | CRITICAL | 9.0 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. … | Aug 15, 2026 |
| CVE-2026-73047 | MEDIUM | 6.2 | siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature (introduced in v3.7.0-beta.1). The feature's template … | Aug 15, 2026 |
| CVE-2026-73046 | CRITICAL | 9.8 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts … | Aug 15, 2026 |
| CVE-2026-73045 | HIGH | 7.5 | SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. … | Aug 15, 2026 |
| CVE-2026-73044 | CRITICAL | 9.0 | SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious … | Aug 15, 2026 |
| CVE-2026-73043 | CRITICAL | 9.0 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without … | Aug 15, 2026 |
| CVE-2026-73042 | CRITICAL | 9.0 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or … | Aug 15, 2026 |
| CVE-2026-73041 | CRITICAL | 9.0 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation … | Aug 15, 2026 |
| CVE-2026-19916 | LOW | 3.5 | A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation … | Aug 15, 2026 |
| CVE-2026-19906 | LOW | 3.7 | A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. … | Aug 15, 2026 |
| CVE-2026-19905 | HIGH | 7.3 | A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes … | Aug 15, 2026 |