CVE Vulnerability Database
Search and browse 378,471 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69085 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s... |
| CVE-2026-69084 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement... |
| CVE-2026-69083 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable... |
| CVE-2026-68587 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea... |
| CVE-2026-68586 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints... |
| CVE-2026-68585 | MEDIUM | 6.9 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r... |
| CVE-2026-68584 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end... |
| CVE-2026-67608 | HIGH | 8.6 | — | Aug 3, 2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti... |
| CVE-2026-64827 | CRITICAL | 9.8 | 0.4% | Aug 3, 2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp... |
| CVE-2026-18642 | HIGH | 7.8 | — | Aug 3, 2026 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock ... |
| CVE-2026-18601 | CRITICAL | 9.8 | 2.4% | Aug 3, 2026 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi... |
| CVE-2026-18600 | HIGH | 8.8 | 2.0% | Aug 3, 2026 | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s... |
| CVE-2026-18108 | CRITICAL | 9.8 | 0.2% | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr... |
| CVE-2026-18092 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm... |
| CVE-2026-18089 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em... |
| CVE-2026-56609 | MEDIUM | 6.5 | 0.1% | Aug 3, 2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using... |
| CVE-2026-56608 | MEDIUM | 5.3 | 0.2% | Aug 3, 2026 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce... |
| CVE-2026-2346 | CRITICAL | 9.8 | — | Aug 3, 2026 | Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ... |
| CVE-2026-18599 | HIGH | 8 | 1.4% | Aug 3, 2026 | A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f... |
| CVE-2026-18598 | HIGH | 8.8 | 1.7% | Aug 3, 2026 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l... |
| CVE-2026-18574 | CRITICAL | 9.3 | 1.0% | Aug 3, 2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se... |
| CVE-2026-69082 | HIGH | 8.8 | — | Aug 3, 2026 | CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. Th... |
| CVE-2026-69079 | HIGH | 8.7 | — | Aug 3, 2026 | CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endp... |
| CVE-2026-69078 | HIGH | 8.8 | — | Aug 3, 2026 | CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functio... |
| CVE-2026-68742 | MEDIUM | 5.5 | 0.1% | Aug 3, 2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen ... |
