Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74799 | CRITICAL | 9.3 | SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers … | Aug 17, 2026 |
| CVE-2026-74798 | HIGH | 8.7 | SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter … | Aug 17, 2026 |
| CVE-2026-74845 | HIGH | 8.8 | Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, … | Aug 17, 2026 |
| CVE-2026-58561 | MEDIUM | 4.0 | Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-58560 | MEDIUM | 4.0 | Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49308 | MEDIUM | 5.5 | Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Aug 17, 2026 |
| CVE-2026-49307 | MEDIUM | 6.2 | Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Aug 17, 2026 |
| CVE-2026-49306 | LOW | 3.3 | UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49305 | MEDIUM | 6.2 | Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49304 | MEDIUM | 6.2 | Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49303 | MEDIUM | 5.1 | Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49302 | MEDIUM | 6.2 | Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Aug 17, 2026 |
| CVE-2026-49301 | MEDIUM | 6.2 | Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Aug 17, 2026 |
| CVE-2026-20000 | MEDIUM | 6.3 | A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the … | Aug 17, 2026 |
| CVE-2026-19999 | MEDIUM | 6.3 | A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp … | Aug 17, 2026 |
| CVE-2026-19998 | MEDIUM | 4.3 | A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the … | Aug 17, 2026 |
| CVE-2026-22072 | UNKNOWN | — | Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens. | Aug 17, 2026 |
| CVE-2026-19997 | MEDIUM | 4.7 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component … | Aug 17, 2026 |
| CVE-2026-19996 | MEDIUM | 4.3 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior … | Aug 17, 2026 |
| CVE-2026-19995 | LOW | 3.5 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. … | Aug 17, 2026 |
| CVE-2026-19994 | MEDIUM | 6.3 | A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component … | Aug 17, 2026 |
| CVE-2026-15623 | UNKNOWN | — | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform … | Aug 17, 2026 |
| CVE-2026-74579 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field offload nft_payload_offload_mask() builds the offload match mask … | Aug 17, 2026 |
| CVE-2026-19993 | MEDIUM | 4.3 | A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the … | Aug 17, 2026 |
| CVE-2026-19992 | LOW | 3.1 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown … | Aug 17, 2026 |