Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

CVEs (442)

Showing 101–125 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2026-72796 MEDIUM 5.8 2026-08-12 SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Att…
CVE-2026-72795 HIGH 8.6 2026-08-12 SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request…
CVE-2026-72794 HIGH 8.6 2026-08-12 siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retriev…
CVE-2026-72793 HIGH 8.6 2026-08-12 SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the sess…
CVE-2026-72792 MEDIUM 5.8 2026-08-12 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected …
CVE-2026-72791 MEDIUM Patched 5.8 2026-08-12 SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in the /api/av/getAttributeV…
CVE-2026-72790 MEDIUM 5.8 2026-08-12 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization che…
CVE-2026-72789 HIGH 8.6 2026-08-12 SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and…
CVE-2026-72788 MEDIUM 5.8 2026-08-12 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publ…
CVE-2026-72787 MEDIUM Patched 6.4 2026-08-12 Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element ch…
CVE-2026-72786 MEDIUM Patched 6.5 2026-08-12 Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without veri…
CVE-2026-72508 CRITICAL 9.9 2026-08-12 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to pe…
CVE-2026-6821 MEDIUM Patched 4.3 2026-08-12 GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could h…
CVE-2026-67579 HIGH Patched 7.4 2026-08-12 Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination curso…
CVE-2026-63300 CRITICAL 9.9 2026-08-12 An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permiss…
CVE-2026-63299 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource lim…
CVE-2026-63298 CRITICAL 9.9 2026-08-12 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configurat…
CVE-2026-63297 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during…
CVE-2026-63296 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to…
CVE-2026-63295 MEDIUM 4.3 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with re…
CVE-2026-63294 CRITICAL 9.9 2026-08-12 A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup arc…
CVE-2026-63293 CRITICAL 9.9 2026-08-12 A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archiv…
CVE-2026-62420 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When …
CVE-2026-59917 HIGH Patched 7.8 2026-08-12 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access c…
CVE-2026-59916 HIGH Patched 7.8 2026-08-12 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access c…