Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47870
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72830 | CRITICAL | 9.8 | Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers … | Aug 14, 2026 |
| CVE-2026-72829 | CRITICAL | 9.8 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only … | Aug 14, 2026 |
| CVE-2026-72828 | HIGH | 7.2 | Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() … | Aug 14, 2026 |
| CVE-2026-72827 | HIGH | 8.8 | Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can … | Aug 14, 2026 |
| CVE-2026-72826 | CRITICAL | 9.8 | The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in … | Aug 14, 2026 |
| CVE-2026-72825 | HIGH | 7.6 | The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare … | Aug 14, 2026 |
| CVE-2026-72824 | CRITICAL | 9.8 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does … | Aug 14, 2026 |
| CVE-2026-72823 | MEDIUM | 5.4 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before … | Aug 14, 2026 |
| CVE-2026-72822 | CRITICAL | 9.8 | The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, … | Aug 14, 2026 |
| CVE-2026-72821 | MEDIUM | 5.4 | Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. … | Aug 14, 2026 |
| CVE-2026-72820 | MEDIUM | 4.9 | Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. … | Aug 14, 2026 |
| CVE-2026-72819 | HIGH | 8.8 | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code … | Aug 14, 2026 |
| CVE-2026-72817 | MEDIUM | 6.5 | go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP … | Aug 14, 2026 |
| CVE-2026-72816 | MEDIUM | 6.5 | go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites … | Aug 14, 2026 |
| CVE-2026-72815 | UNKNOWN | — | go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of … | Aug 14, 2026 |
| CVE-2026-72814 | UNKNOWN | — | The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the … | Aug 14, 2026 |
| CVE-2026-72813 | UNKNOWN | — | actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set … | Aug 14, 2026 |
| CVE-2026-72812 | MEDIUM | 6.5 | SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke … | Aug 14, 2026 |
| CVE-2026-72811 | CRITICAL | 10.0 | SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) … | Aug 14, 2026 |
| CVE-2026-72810 | HIGH | 8.6 | SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a … | Aug 14, 2026 |
| CVE-2026-19822 | HIGH | 8.8 | A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation … | Aug 14, 2026 |
| CVE-2025-71405 | UNKNOWN | — | chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can … | Aug 14, 2026 |
| CVE-2026-19821 | HIGH | 8.8 | A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. … | Aug 14, 2026 |
| CVE-2026-19815 | HIGH | 8.8 | A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. … | Aug 14, 2026 |
| CVE-2026-19814 | HIGH | 8.8 | A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of … | Aug 14, 2026 |