Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48747
Total
3915
Critical
14448
High
14180
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72797 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. … | Aug 12, 2026 |
| CVE-2026-72796 | MEDIUM | 5.8 | SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers … | Aug 12, 2026 |
| CVE-2026-72795 | HIGH | 8.6 | SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing … | Aug 12, 2026 |
| CVE-2026-72794 | HIGH | 8.6 | siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey … | Aug 12, 2026 |
| CVE-2026-72793 | HIGH | 8.6 | SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, … | Aug 12, 2026 |
| CVE-2026-72792 | MEDIUM | 5.8 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. … | Aug 12, 2026 |
| CVE-2026-72791 | MEDIUM | 5.8 | SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in the /api/av/getAttributeViewFieldViews endpoint. The route … | Aug 12, 2026 |
| CVE-2026-72790 | MEDIUM | 5.8 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document … | Aug 12, 2026 |
| CVE-2026-72789 | HIGH | 8.6 | SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve … | Aug 12, 2026 |
| CVE-2026-72788 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated … | Aug 12, 2026 |
| CVE-2026-72787 | MEDIUM | 6.4 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element … | Aug 12, 2026 |
| CVE-2026-72786 | MEDIUM | 6.5 | Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with … | Aug 12, 2026 |
| CVE-2026-72508 | CRITICAL | 9.9 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy … | Aug 12, 2026 |
| CVE-2026-6821 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-67579 | UNKNOWN | — | Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in … | Aug 12, 2026 |
| CVE-2026-63300 | CRITICAL | 9.9 | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass … | Aug 12, 2026 |
| CVE-2026-63299 | CRITICAL | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource … | Aug 12, 2026 |
| CVE-2026-63298 | CRITICAL | 9.9 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline … | Aug 12, 2026 |
| CVE-2026-63297 | CRITICAL | 9.9 | An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project … | Aug 12, 2026 |
| CVE-2026-63296 | CRITICAL | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target … | Aug 12, 2026 |
| CVE-2026-63295 | MEDIUM | 4.3 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container … | Aug 12, 2026 |
| CVE-2026-63294 | CRITICAL | 9.9 | A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted … | Aug 12, 2026 |
| CVE-2026-63293 | CRITICAL | 9.9 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking … | Aug 12, 2026 |
| CVE-2026-62420 | CRITICAL | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project … | Aug 12, 2026 |
| CVE-2026-59917 | HIGH | 7.8 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially … | Aug 12, 2026 |