Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48747
Total
3915
Critical
14448
High
14180
Medium
CVE ID Severity Score Description Published
CVE-2026-73407 UNKNOWN Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to … Aug 12, 2026
CVE-2026-73406 HIGH 7.5 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An … Aug 12, 2026
CVE-2026-73332 HIGH 8.7 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to … Aug 12, 2026
CVE-2026-73331 HIGH 7.1 CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing … Aug 12, 2026
CVE-2026-73330 MEDIUM 6.6 CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of … Aug 12, 2026
CVE-2026-73329 HIGH 8.7 CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads … Aug 12, 2026
CVE-2026-73326 HIGH 7.6 CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without … Aug 12, 2026
CVE-2026-73308 MEDIUM 5.7 Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress … Aug 12, 2026
CVE-2026-73307 UNKNOWN Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in … Aug 12, 2026
CVE-2026-73306 MEDIUM 5.3 Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/emailLockout.ts returned X-Account-Locked … Aug 12, 2026
CVE-2026-73303 HIGH 8.2 Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while … Aug 12, 2026
CVE-2026-73269 CRITICAL 9.9 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation … Aug 12, 2026
CVE-2026-73268 CRITICAL 9.9 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an … Aug 12, 2026
CVE-2026-72809 HIGH 8.0 SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any … Aug 12, 2026
CVE-2026-72808 MEDIUM 5.8 SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content … Aug 12, 2026
CVE-2026-72807 HIGH 8.0 SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string … Aug 12, 2026
CVE-2026-72806 MEDIUM 5.8 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and … Aug 12, 2026
CVE-2026-72805 MEDIUM 5.8 SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers … Aug 12, 2026
CVE-2026-72804 HIGH 8.6 SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers … Aug 12, 2026
CVE-2026-72803 MEDIUM 5.8 SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and … Aug 12, 2026
CVE-2026-72802 MEDIUM 5.3 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest … Aug 12, 2026
CVE-2026-72801 HIGH 7.5 SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, … Aug 12, 2026
CVE-2026-72800 MEDIUM 5.8 SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select … Aug 12, 2026
CVE-2026-72799 MEDIUM 5.8 SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when … Aug 12, 2026
CVE-2026-72798 HIGH 8.6 SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or … Aug 12, 2026