Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85606 HIGH 7.5 2026-09-04 firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory …
CVE-2026-85605 MEDIUM Patched 5.3 2026-09-04 Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/c…
CVE-2026-85604 HIGH Patched 8.8 2026-09-04 Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes&hellip;
CVE-2026-85603 MEDIUM Patched 6.5 2026-09-04 Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticate&hellip;
CVE-2026-85602 MEDIUM Patched 5.3 2026-09-04 The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present i&hellip;
CVE-2026-85601 MEDIUM Patched 5.4 2026-09-04 Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal co&hellip;
CVE-2026-85600 MEDIUM Patched 5.4 2026-09-04 Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), whic&hellip;
CVE-2026-85599 HIGH Patched 7.2 2026-09-04 Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rende&hellip;
CVE-2026-85598 MEDIUM 6.4 2026-09-04 Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attacke&hellip;
CVE-2026-85597 NONE &mdash; 2026-09-04 Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate&hellip;
CVE-2026-85596 NONE Patched &mdash; 2026-09-04 Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the ng&hellip;
CVE-2026-85595 NONE &mdash; 2026-09-04 Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames rec&hellip;
CVE-2026-85594 NONE &mdash; 2026-09-04 Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kuberne&hellip;
CVE-2026-85593 MEDIUM Patched 5.4 2026-09-04 phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ &hellip;
CVE-2026-85592 LOW Patched 3.7 2026-09-04 phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all call&hellip;
CVE-2026-85591 NONE Patched &mdash; 2026-09-04 phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account p&hellip;
CVE-2026-85590 NONE Patched &mdash; 2026-09-04 phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (re&hellip;
CVE-2026-85589 NONE Patched &mdash; 2026-09-04 phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authenticati&hellip;
CVE-2026-85588 NONE Patched &mdash; 2026-09-04 phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP s&hellip;
CVE-2026-85587 NONE Patched &mdash; 2026-09-04 phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with onl&hellip;
CVE-2026-85586 NONE Patched &mdash; 2026-09-04 phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTC&hellip;
CVE-2026-85585 HIGH 7.5 2026-09-04 SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path&hellip;
CVE-2026-85584 HIGH 7.5 2026-09-04 SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlle&hellip;
CVE-2026-85583 MEDIUM 6.5 2026-09-04 SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. &hellip;
CVE-2026-85582 MEDIUM 6.5 2026-09-04 SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust m&hellip;