Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85602 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present i… |
| CVE-2026-85601 | MEDIUM | Patched | 5.4 | 2026-09-04 | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal co… |
| CVE-2026-85600 | MEDIUM | Patched | 5.4 | 2026-09-04 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), whic… |
| CVE-2026-85599 | HIGH | Patched | 7.2 | 2026-09-04 | Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rende… |
| CVE-2026-85598 | MEDIUM | 6.4 | 2026-09-04 | Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attacke… | |
| CVE-2026-85597 | NONE | — | 2026-09-04 | Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate… | |
| CVE-2026-85596 | NONE | Patched | — | 2026-09-04 | Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the ng… |
| CVE-2026-85595 | NONE | — | 2026-09-04 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames rec… | |
| CVE-2026-85594 | NONE | — | 2026-09-04 | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kuberne… | |
| CVE-2026-85593 | MEDIUM | Patched | 5.4 | 2026-09-04 | phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ … |
| CVE-2026-85592 | LOW | Patched | 3.7 | 2026-09-04 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call… |
| CVE-2026-85591 | NONE | Patched | — | 2026-09-04 | phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account p… |
| CVE-2026-85590 | NONE | Patched | — | 2026-09-04 | phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (re… |
| CVE-2026-85589 | NONE | Patched | — | 2026-09-04 | phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authenticati… |
| CVE-2026-85588 | NONE | Patched | — | 2026-09-04 | phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP s… |
| CVE-2026-85587 | NONE | Patched | — | 2026-09-04 | phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with onl… |
| CVE-2026-85586 | NONE | Patched | — | 2026-09-04 | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTC… |
| CVE-2026-85585 | HIGH | 7.5 | 2026-09-04 | SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path… | |
| CVE-2026-85584 | HIGH | 7.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlle… | |
| CVE-2026-85583 | MEDIUM | 6.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. … | |
| CVE-2026-85582 | MEDIUM | 6.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust m… | |
| CVE-2026-85581 | HIGH | 7.5 | 2026-09-04 | SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process iden… | |
| CVE-2026-85580 | MEDIUM | 6.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can… | |
| CVE-2026-85579 | MEDIUM | Patched | 4.3 | 2026-09-04 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The… |
| CVE-2026-85578 | MEDIUM | 6.5 | 2026-09-04 | SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly config… |