Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50129
Total
4051
Critical
14904
High
14658
Medium
CVE ID Severity Score Description Published
CVE-2026-69093 MEDIUM 4.6 Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An … Aug 03, 2026
CVE-2026-69092 MEDIUM 6.5 Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers … Aug 03, 2026
CVE-2026-69091 HIGH 7.5 Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to … Aug 03, 2026
CVE-2026-69090 MEDIUM 4.9 Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to … Aug 03, 2026
CVE-2026-69089 HIGH 7.5 Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically … Aug 03, 2026
CVE-2026-69088 HIGH 8.1 Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist … Aug 03, 2026
CVE-2026-69087 MEDIUM 6.5 The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, … Aug 03, 2026
CVE-2026-69086 HIGH 7.7 SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that … Aug 03, 2026
CVE-2026-69085 CRITICAL 10.0 SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no … Aug 03, 2026
CVE-2026-69084 CRITICAL 10.0 SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, … Aug 03, 2026
CVE-2026-69083 CRITICAL 10.0 SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL … Aug 03, 2026
CVE-2026-68587 HIGH 8.6 SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous … Aug 03, 2026
CVE-2026-68586 HIGH 8.6 SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter … Aug 03, 2026
CVE-2026-68585 MEDIUM 5.8 SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access … Aug 03, 2026
CVE-2026-68584 HIGH 8.6 SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting … Aug 03, 2026
CVE-2026-67608 HIGH 7.2 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated … Aug 03, 2026
CVE-2026-64827 CRITICAL 9.8 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function … Aug 03, 2026
CVE-2026-18642 HIGH 7.8 Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4. Aug 03, 2026
CVE-2026-18601 CRITICAL 9.8 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. … Aug 03, 2026
CVE-2026-18600 HIGH 8.8 A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua … Aug 03, 2026
CVE-2026-18108 CRITICAL 9.8 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and … Aug 03, 2026
CVE-2026-18092 HIGH 8.1 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the … Aug 03, 2026
CVE-2026-18089 HIGH 7.5 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. … Aug 03, 2026
CVE-2026-56609 MEDIUM 4.8 HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 … Aug 03, 2026
CVE-2026-56608 LOW 3.7 HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level … Aug 03, 2026