Total
9883 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-72795 | 2026-08-26 | N/A | 8.6 HIGH | ||
| SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization. | |||||
| CVE-2026-72806 | 2026-08-26 | N/A | 5.8 MEDIUM | ||
| SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows including titles, block IDs, and column values by calling renderAttributeView without supplying the required password. | |||||
| CVE-2026-72808 | 2026-08-26 | N/A | 5.8 MEDIUM | ||
| SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content without a publish-access check. Because the endpoint is gated only by CheckAuth (unlike the /assets/* route, which enforces publish access and password), an anonymous reader (when publish authentication is disabled) or any publish RoleReader who knows an asset path can read the private PDF annotations (highlights and notes) of publish-forbidden, password-protected, or unpublished documents. The issue is limited to non-encrypted notebooks; encrypted-box annotations are not exposed. | |||||
| CVE-2026-72803 | 2026-08-26 | N/A | 5.8 MEDIUM | ||
| SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs. | |||||
| CVE-2026-73326 | 2026-08-26 | N/A | 7.6 HIGH | ||
| CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to alter cached page behavior, modify public meta-tag output, or reconfigure contact forms, enabling account takeover when chained with stored cross-site scripting through the contact form's before_html field. | |||||
| CVE-2026-72796 | 2026-08-26 | N/A | 5.8 MEDIUM | ||
| SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets, and export artifacts by directly accessing static routes that lack the same restrictions as their REST API counterparts. | |||||
| CVE-2026-58434 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Private Repository Metadata Remains Accessible After Access Revocation | |||||
| CVE-2026-57886 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| Cross-repository issue/comment attachment re-linking can expose private attachment content | |||||
| CVE-2026-58432 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | |||||
| CVE-2026-58433 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | |||||
| CVE-2026-58438 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | |||||
| CVE-2026-50105 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | |||||
| CVE-2026-72900 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. | |||||
| CVE-2026-75932 | 2026-08-26 | N/A | 8.6 HIGH | ||
| Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider. | |||||
| CVE-2026-75866 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in the request body, so a client registered for authorization_code alone can ask for client_credentials, and that arm passes the requested scope straight to the minter, which signs it into the at+jwt access token. authorize copies the query scope into the authorization code record without comparing it against the registration, leaving the optional consent hook as the only check between an arbitrary scope and the issued code. redirect_uris on the same client row is read and enforced. A registered client can obtain a correctly signed token carrying any scope it names, and a resource server running Punk::OAuth2::Checker accepts that token and honours the scope. A client registered without a secret authenticates on its client_id alone, so anyone who knows that identifier can request one. | |||||
| CVE-2026-16471 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8. | |||||
| CVE-2026-16467 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9. | |||||
| CVE-2026-18650 | 2026-08-26 | N/A | 8.8 HIGH | ||
| Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |||||
| CVE-2026-17070 | 2026-08-26 | N/A | 8.8 HIGH | ||
| Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |||||
| CVE-2026-73405 | 2026-08-26 | N/A | N/A | ||
| An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint. The token_required decorator used by the Pub/Sub interface authenticated requests solely by matching the X-API-KEY header against an existing user API key. Unlike the REST API authentication mechanism, it did not verify the account's is_active and is_confirmed state. Because the self-registration process issues an API key before account confirmation is completed, an attacker could create an account and immediately use the resulting API key to access Pub/Sub topics that should only be available to active, confirmed users. This could expose stream events that would otherwise be inaccessible through the REST API, including newly submitted or not-yet-moderated data such as comments. The vulnerability results from inconsistent authorization enforcement between the REST API and the SSE streaming interface. The patch corrects the issue by requiring accounts to be both active and confirmed before permitting access to Pub/Sub streams, bringing the SSE authorization boundary in line with the REST API. | |||||
