Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 101–125 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-72796 | MEDIUM | 5.8 | 2026-08-12 | SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Att… | |
| CVE-2026-72795 | HIGH | 8.6 | 2026-08-12 | SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request… | |
| CVE-2026-72794 | HIGH | 8.6 | 2026-08-12 | siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retriev… | |
| CVE-2026-72793 | HIGH | 8.6 | 2026-08-12 | SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the sess… | |
| CVE-2026-72792 | MEDIUM | 5.8 | 2026-08-12 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected … | |
| CVE-2026-72791 | MEDIUM | Patched | 5.8 | 2026-08-12 | SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in the /api/av/getAttributeV… |
| CVE-2026-72790 | MEDIUM | 5.8 | 2026-08-12 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization che… | |
| CVE-2026-72789 | HIGH | 8.6 | 2026-08-12 | SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and… | |
| CVE-2026-72788 | MEDIUM | 5.8 | 2026-08-12 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publ… | |
| CVE-2026-72787 | MEDIUM | Patched | 6.4 | 2026-08-12 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element ch… |
| CVE-2026-72786 | MEDIUM | Patched | 6.5 | 2026-08-12 | Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without veri… |
| CVE-2026-72508 | CRITICAL | 9.9 | 2026-08-12 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to pe… | |
| CVE-2026-6821 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could h… |
| CVE-2026-67579 | HIGH | Patched | 7.4 | 2026-08-12 | Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination curso… |
| CVE-2026-63300 | CRITICAL | 9.9 | 2026-08-12 | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permiss… | |
| CVE-2026-63299 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource lim… | |
| CVE-2026-63298 | CRITICAL | 9.9 | 2026-08-12 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configurat… | |
| CVE-2026-63297 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during… | |
| CVE-2026-63296 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to… | |
| CVE-2026-63295 | MEDIUM | 4.3 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with re… | |
| CVE-2026-63294 | CRITICAL | 9.9 | 2026-08-12 | A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup arc… | |
| CVE-2026-63293 | CRITICAL | 9.9 | 2026-08-12 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archiv… | |
| CVE-2026-62420 | CRITICAL | 9.9 | 2026-08-12 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When … | |
| CVE-2026-59917 | HIGH | Patched | 7.8 | 2026-08-12 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access c… |
| CVE-2026-59916 | HIGH | Patched | 7.8 | 2026-08-12 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access c… |