Total
2632 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-73606 | 2026-08-26 | N/A | 5.8 MEDIUM | ||
| SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password. | |||||
| CVE-2026-73610 | 2026-08-26 | N/A | 5.8 MEDIUM | ||
| SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map with only three keys sanitized. Unauthenticated attackers or publish readers can retrieve closed-tab history, search keywords, private document identifiers, and expanded folder paths by calling the getLocalStorage endpoint. | |||||
| CVE-2026-72802 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest relative asset paths from published documents and submit them to resolveAssetPath to obtain the server's absolute workspace path, disclosing the operating-system username and installation layout. | |||||
| CVE-2026-57886 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| Cross-repository issue/comment attachment re-linking can expose private attachment content | |||||
| CVE-2026-58445 | 2026-08-26 | N/A | 2.7 LOW | ||
| Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | |||||
| CVE-2026-58432 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | |||||
| CVE-2026-58435 | 2026-08-26 | N/A | 5.4 MEDIUM | ||
| Gitea LFS Deploy-Key Privilege Escalation | |||||
| CVE-2026-16309 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7. | |||||
| CVE-2026-2346 | 2026-08-26 | N/A | 9.8 CRITICAL | ||
| Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026. | |||||
| CVE-2026-19424 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data. | |||||
| CVE-2026-75950 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings. | |||||
| CVE-2026-75951 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | |||||
| CVE-2026-67360 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked. | |||||
| CVE-2026-67358 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also lacked a CSRF token. | |||||
| CVE-2026-67359 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to render the full checkout confirmation page for that order, including line items, prices, and totals. | |||||
| CVE-2026-14938 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site. | |||||
| CVE-2026-15209 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | |||||
| CVE-2026-14197 | 2026-08-26 | N/A | 3.8 LOW | ||
| The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope. | |||||
| CVE-2026-16291 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. | |||||
| CVE-2026-14195 | 2026-08-26 | N/A | 2.7 LOW | ||
| The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts. | |||||
