Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

CVEs (442)

Showing 76–100 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2026-73406 HIGH Patched 7.5 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and ten…
CVE-2026-73332 HIGH 8.7 2026-08-12 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML…
CVE-2026-73331 HIGH 7.1 2026-08-12 CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slu…
CVE-2026-73330 MEDIUM 6.6 2026-08-12 CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in th…
CVE-2026-73329 HIGH 8.7 2026-08-12 CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browse…
CVE-2026-73326 HIGH 7.6 2026-08-12 CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotect…
CVE-2026-73308 MEDIUM Patched 5.7 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.output…
CVE-2026-73307 NONE Patched — 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment v…
CVE-2026-73306 MEDIUM Patched 5.3 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers…
CVE-2026-73303 HIGH Patched 8.2 2026-08-12 Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the a…
CVE-2026-73269 CRITICAL 9.9 2026-08-12 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creatio…
CVE-2026-73268 CRITICAL 9.9 2026-08-12 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject…
CVE-2026-72809 HIGH Patched 8.0 2026-08-12 SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAd&hellip;
CVE-2026-72808 MEDIUM Patched 5.8 2026-08-12 SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sy&hellip;
CVE-2026-72807 HIGH 8.0 2026-08-12 SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw&hellip;
CVE-2026-72806 MEDIUM 5.8 2026-08-12 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when re&hellip;
CVE-2026-72805 MEDIUM 5.8 2026-08-12 SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected doc&hellip;
CVE-2026-72804 HIGH 8.6 2026-08-12 SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of &hellip;
CVE-2026-72803 MEDIUM 5.8 2026-08-12 SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including&hellip;
CVE-2026-72802 MEDIUM 5.3 2026-08-12 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAut&hellip;
CVE-2026-72801 HIGH 7.5 2026-08-12 SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can ret&hellip;
CVE-2026-72800 MEDIUM 5.8 2026-08-12 SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database &hellip;
CVE-2026-72799 MEDIUM 5.8 2026-08-12 SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, ge&hellip;
CVE-2026-72798 HIGH 8.6 2026-08-12 SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell content&hellip;
CVE-2026-72797 MEDIUM 5.8 2026-08-12 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names,&hellip;