Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-85582 — SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth

SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeat…

Remote | Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-85581 — SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits…

Remote | Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-85580 — SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publish…

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-85579 — SiYuan before v3.8.2 Information Disclosure via undoState

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekM…

Remote | Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-85578 — SiYuan through 3.8.1 Authorization Bypass via getFile

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Atta…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.4 MEDIUM
CVE-2026-85577 — AVideo userLogin.php Reflected XSS via error parameter

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag…

avideo | Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-19080 — Username Enumeration in Menulux Software's Menulux Portal

Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.

Remote | Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-19051 — Plaintext Storage of User Credentials in Menulux Software's Menulux Portal

Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448.

Remote | Cryptography
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
4.3 MEDIUM
CVE-2026-19043 — Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Port…

Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448.

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.4 MEDIUM
CVE-2026-18957 — Stored XSS in Menulux Software's Menulux Portal

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: befor…

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.9 MEDIUM
CVE-2026-85534 — Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initi…

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicio…

enterprise_linux enterprise_linux | Remote | Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-85512 — SourceCodester Class and Exam Timetabling System session.php authorization

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument I…

class_and_exam_timetabling_system | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-84428 — fastify vulnerable to header validation bypass via incomplete schema case normalization

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-84045 — E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation v…

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing un…

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-79707 — Arbitrary File Read in Google Agent Development Kit (ADK)

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary …

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.5 HIGH
CVE-2026-4644 — Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privilege…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-27347 — WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.

jetpopup | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.2 MEDIUM
CVE-2026-85547 — Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISP

A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP'…

Remote | Cross-Site Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.6 HIGH
CVE-2026-85546 — MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuick…

Remote | Cross-Site Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.4 MEDIUM
CVE-2026-85541 — Interinfo|DreamMaker - Reflected Cross-site Scripting

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12549 Results