Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48124
Total
3850
Critical
14244
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73613 | HIGH | 8.2 | filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission … | Aug 13, 2026 |
| CVE-2026-73612 | HIGH | 8.1 | File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access … | Aug 13, 2026 |
| CVE-2026-73611 | MEDIUM | 6.8 | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a … | Aug 13, 2026 |
| CVE-2026-73610 | MEDIUM | 5.8 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map with only three keys sanitized. … | Aug 13, 2026 |
| CVE-2026-73609 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous … | Aug 13, 2026 |
| CVE-2026-73608 | HIGH | 8.6 | SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. … | Aug 13, 2026 |
| CVE-2026-73607 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading … | Aug 13, 2026 |
| CVE-2026-73606 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that … | Aug 13, 2026 |
| CVE-2026-73605 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. … | Aug 13, 2026 |
| CVE-2026-73604 | MEDIUM | 6.5 | Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission … | Aug 13, 2026 |
| CVE-2026-73603 | UNKNOWN | — | Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate … | Aug 13, 2026 |
| CVE-2026-73602 | UNKNOWN | — | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale … | Aug 13, 2026 |
| CVE-2026-73601 | UNKNOWN | — | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to … | Aug 13, 2026 |
| CVE-2026-73488 | UNKNOWN | — | Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment … | Aug 13, 2026 |
| CVE-2026-73487 | UNKNOWN | — | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via … | Aug 13, 2026 |
| CVE-2026-73486 | UNKNOWN | — | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The … | Aug 13, 2026 |
| CVE-2026-73485 | UNKNOWN | — | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the … | Aug 13, 2026 |
| CVE-2026-73484 | UNKNOWN | — | Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated … | Aug 13, 2026 |
| CVE-2026-73483 | UNKNOWN | — | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the … | Aug 13, 2026 |
| CVE-2026-45819 | UNKNOWN | — | baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. | Aug 13, 2026 |
| CVE-2026-18368 | UNKNOWN | — | In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access … | Aug 13, 2026 |
| CVE-2026-16455 | UNKNOWN | — | In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged … | Aug 13, 2026 |
| CVE-2026-12263 | HIGH | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. | Aug 13, 2026 |
| CVE-2026-59507 | CRITICAL | 9.3 | CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control | Aug 13, 2026 |
| CVE-2026-59506 | CRITICAL | 9.3 | CWE-306: Missing Authentication for Critical Function | Aug 13, 2026 |