Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.7
CVE-2026-73329

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.6
CVE-2026-73326

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.7
CVE-2026-73308

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results co…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73306

Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/wor…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 8.2
CVE-2026-73303

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId with…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, …

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73268

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.0
CVE-2026-72809

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the adm…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72808

SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endp…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.0
CVE-2026-72807

SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks funct…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72806

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish pass…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72805

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disc…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72804

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72803

SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve blo…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-72802

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-72801

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72800

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retr…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72799

SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPa…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72798

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72797

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted noteb…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72796

SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforc…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72795

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72794

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72793

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader u…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72792

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts f…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72791

SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in th…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72790

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata wi…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72789

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous re…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72788

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator wo…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.4
CVE-2026-72787

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML…

No fix yet
Fix from $4,000 2026-08-12