Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47944
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-73608 HIGH 8.6 SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. … Aug 13, 2026
CVE-2026-73607 MEDIUM 5.8 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading … Aug 13, 2026
CVE-2026-73606 MEDIUM 5.8 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that … Aug 13, 2026
CVE-2026-73605 MEDIUM 5.8 SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. … Aug 13, 2026
CVE-2026-73604 MEDIUM 6.5 Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission … Aug 13, 2026
CVE-2026-73603 UNKNOWN Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate … Aug 13, 2026
CVE-2026-73602 UNKNOWN Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale … Aug 13, 2026
CVE-2026-73601 UNKNOWN Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to … Aug 13, 2026
CVE-2026-73488 UNKNOWN Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment … Aug 13, 2026
CVE-2026-73487 UNKNOWN Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via … Aug 13, 2026
CVE-2026-73486 UNKNOWN Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The … Aug 13, 2026
CVE-2026-73485 UNKNOWN Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the … Aug 13, 2026
CVE-2026-73484 UNKNOWN Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated … Aug 13, 2026
CVE-2026-73483 UNKNOWN Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the … Aug 13, 2026
CVE-2026-45819 UNKNOWN baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. Aug 13, 2026
CVE-2026-18368 UNKNOWN In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access … Aug 13, 2026
CVE-2026-16455 UNKNOWN In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged … Aug 13, 2026
CVE-2026-12263 HIGH 8.8 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. Aug 13, 2026
CVE-2026-59507 CRITICAL 9.3 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59506 CRITICAL 9.3 CWE-306: Missing Authentication for Critical Function Aug 13, 2026
CVE-2026-59505 HIGH 8.6 CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59504 CRITICAL 9.1 CWE-602: Client-Side Enforcement of Server-Side Security Aug 13, 2026
CVE-2026-59503 CRITICAL 9.1 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor Aug 13, 2026
CVE-2026-59502 MEDIUM 5.3 CWE-203: Observable Discrepancy Aug 13, 2026
CVE-2026-59501 HIGH 8.2 CWE-284: Improper Access Control Aug 13, 2026