Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-72798 SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72797 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted noteb… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72796 SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforc… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72795 SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints… No fix yet Fix from $4,9002026-08-12 HIGH 8.6 CVE-2026-72794 siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode… No fix yet Fix from $4,9002026-08-12 HIGH 8.6 CVE-2026-72793 SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader u… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72792 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts f… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72791 SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in th… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72790 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata wi… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72789 SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous re… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72788 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator wo… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.4 CVE-2026-72787 Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-72786 Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.9 CVE-2026-72508 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a names… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63299 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63298 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63297 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63296 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63294 A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63293 A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un… No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-49466 Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (X… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-19657 ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visitin… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.9 CVE-2026-19656 ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.3 CVE-2026-18150 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition. I No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-18099 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-cont… I No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-17642 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem… I No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-17445 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-su… I No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-17417 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach… I No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-17111 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta… I No fix yet Fix from $5,7502026-08-12 CRITICAL 9.8 CVE-2026-17083 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. I No fix yet Fix from $5,7502026-08-12