Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-45148 — SiYuan: Broken access control in SiYuan publish-mode Readers can enumerate metadata

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate…

siyuan | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
4.3 MEDIUM
CVE-2026-45147 — SiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.…

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly…

siyuan | Remote | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.4 CRITICAL
CVE-2026-44670 — SiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuan

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.…

siyuan | Remote | Cross-Site Scripting
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.1 HIGH
CVE-2026-44633 — Live Helper Chat: REST API chat update accepts arbitrary chat fields across department bo…

Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in …

live_helper_chat | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.4 CRITICAL
CVE-2026-44592 — Gradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoning

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker with…

Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
3.7 LOW
CVE-2026-44589 — nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)

Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in [email protected] to remediate GHSA-pqhr-mp3f-hrpp (Dmitry Prokhorov / Positive Technologies,…

og_image | Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.4 CRITICAL
CVE-2026-44588 — SiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` int…

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decode…

siyuan | Remote | Cross-Site Scripting
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.3 HIGH
CVE-2026-44586 — SiYuan: Bazaar marketplace renders unescaped package author metadata, allowing XSS and El…

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML wit…

siyuan | Remote | Cross-Site Scripting
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
10.0 CRITICAL
CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secr…

note_mark | Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.6 HIGH
CVE-2026-44522 — Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code …

Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, …

note_mark | Remote | Path Traversal
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.8 CRITICAL
CVE-2026-41315 — mdserver-web: Missing Authorization and Improper Neutralization of Special Elements used …

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond a…

mdserver-web | Remote | Authentication
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
5.3 MEDIUM
CVE-2026-38740 — Foscam VD1 Cleartext SDP Transmission Vulnerability

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE creden…

Remote | Information Disclosure
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.2 CRITICAL
CVE-2026-27886 — Strapi may leak sensitive data via relational filtering due to lack of query sanitization

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational…

strapi | Remote | Injection
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
4.3 MEDIUM
CVE-2026-27680 — CSS Injection vulnerability in SAP NetWeaver Application Server ABAP

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the appl…

netweaver_application_server_abap | Remote | Cross-Site Scripting
May 14, 2026 Jun 03, 2026
May 14, 2026
Jun 03, 2026
8.2 HIGH
CVE-2026-23998 — Fleet has a Windows MDM management endpoint authentication bypass

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certifi…

fleet | Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
5.4 MEDIUM
CVE-2026-22707 — Strapi Upload Plugin MIME Validation Bypass via Content API

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restr…

strapi | Remote | Misconfiguration
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.5 MEDIUM
CVE-2026-22706 — Strapi: Password Reset Does Not Revoke Existing Refresh Sessions

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions …

strapi | Remote | Authentication
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
9.3 CRITICAL
CVE-2026-22599 — Strapi Vulnerable to SQL Injection in Content Type Builder

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in t…

strapi | Remote | Injection
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.9 MEDIUM
CVE-2025-64526 — Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email …

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx…

strapi | Remote | Authentication
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
7.5 HIGH
CVE-2026-6332 — Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of …

ecostruxure_machine_expert_hvac | Remote | Information Disclosure
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
Showing 20 of 7126 Results