Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-69093 | MEDIUM | 4.6 | Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An … | Aug 03, 2026 |
| CVE-2026-69092 | MEDIUM | 6.5 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers … | Aug 03, 2026 |
| CVE-2026-69091 | HIGH | 7.5 | Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to … | Aug 03, 2026 |
| CVE-2026-69090 | MEDIUM | 4.9 | Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to … | Aug 03, 2026 |
| CVE-2026-69089 | HIGH | 7.5 | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically … | Aug 03, 2026 |
| CVE-2026-69088 | HIGH | 8.1 | Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist … | Aug 03, 2026 |
| CVE-2026-69087 | MEDIUM | 6.5 | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, … | Aug 03, 2026 |
| CVE-2026-69086 | HIGH | 7.7 | SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that … | Aug 03, 2026 |
| CVE-2026-69085 | CRITICAL | 10.0 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no … | Aug 03, 2026 |
| CVE-2026-69084 | CRITICAL | 10.0 | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, … | Aug 03, 2026 |
| CVE-2026-69083 | CRITICAL | 10.0 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL … | Aug 03, 2026 |
| CVE-2026-68587 | HIGH | 8.6 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous … | Aug 03, 2026 |
| CVE-2026-68586 | HIGH | 8.6 | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter … | Aug 03, 2026 |
| CVE-2026-68585 | MEDIUM | 5.8 | SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access … | Aug 03, 2026 |
| CVE-2026-68584 | HIGH | 8.6 | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting … | Aug 03, 2026 |
| CVE-2026-67608 | HIGH | 7.2 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated … | Aug 03, 2026 |
| CVE-2026-64827 | CRITICAL | 9.8 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function … | Aug 03, 2026 |
| CVE-2026-18642 | HIGH | 7.8 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4. | Aug 03, 2026 |
| CVE-2026-18601 | CRITICAL | 9.8 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. … | Aug 03, 2026 |
| CVE-2026-18600 | HIGH | 8.8 | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua … | Aug 03, 2026 |
| CVE-2026-18108 | CRITICAL | 9.8 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and … | Aug 03, 2026 |
| CVE-2026-18092 | HIGH | 8.1 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the … | Aug 03, 2026 |
| CVE-2026-18089 | HIGH | 7.5 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. … | Aug 03, 2026 |
| CVE-2026-56609 | MEDIUM | 4.8 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 … | Aug 03, 2026 |
| CVE-2026-56608 | LOW | 3.7 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level … | Aug 03, 2026 |