CVE Vulnerability Database

Search and browse 378,372 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-69086HIGH8.3SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,...
CVE-2026-69085CRITICAL10SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s...
CVE-2026-69084CRITICAL10SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement...
CVE-2026-69083CRITICAL10SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable...
CVE-2026-68587CRITICAL9.2SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea...
CVE-2026-68586CRITICAL9.2SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints...
CVE-2026-68585MEDIUM6.9SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r...
CVE-2026-68584CRITICAL9.2SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end...
CVE-2026-67608HIGH8.6Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti...
CVE-2026-64827CRITICAL9.8Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp...
CVE-2026-18642HIGH7.8Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock ...
CVE-2026-18601CRITICAL9.8A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi...
CVE-2026-18600HIGH8.8A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s...
CVE-2026-18108CRITICAL9.8Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr...
CVE-2026-18092HIGH8.1Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm...
CVE-2026-18089HIGH7.5Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em...
CVE-2026-56609MEDIUM6.5HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using...
CVE-2026-56608MEDIUM5.3HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce...
CVE-2026-2346CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ...
CVE-2026-18599HIGH8A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f...
CVE-2026-18598HIGH8.8A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l...
CVE-2026-18574CRITICAL9.3An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se...
CVE-2026-69082HIGH8.8CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. Th...
CVE-2026-69079HIGH8.7CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endp...
CVE-2026-69078HIGH8.8CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functio...