Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-74868 — SiYuan before 3.7.4 Brute-Force Authentication via Publish Service

SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go).…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.2 MEDIUM
CVE-2026-74867 — SiYuan before 3.7.4 Cross-Site Request Forgery via CheckAuth

SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authentication branch of CheckAuth() that lacks Origin/Referer validation and sets no explicit Sa…

Remote | Cross-Site Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-74842 — Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side requ…

A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component Image-Toolkit-MCP-Se…

Remote | Server-Side Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.2 HIGH
CVE-2026-74802 — SiYuan 3.7.3 Cross-Site WebSocket Hijacking via network proxy

SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to u…

Remote | Cross-Site Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.2 HIGH
CVE-2026-74801 — SiYuan before 3.7.4 Local Privilege Escalation via elevator.exe

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspac…

| Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.0 CRITICAL
CVE-2026-74800 — SiYuan before v3.7.4 Stored XSS via assets endpoint

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can …

Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.3 CRITICAL
CVE-2026-74799 — SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/ppro…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.7 HIGH
CVE-2026-74798 — SiYuan kernel Path Traversal via database_clean MCP tool

SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedA…

Remote | Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.8 HIGH
CVE-2026-74845 — 2100 Technology|Official Document Management System - Arbitrary File Upload

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.0 MEDIUM
CVE-2026-58561 — Image Codec Module Null Pointer Dereference

Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.0 MEDIUM
CVE-2026-58560 — Image Codec Null Pointer Dereference

Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.5 MEDIUM
CVE-2026-49308 — Clipboard Module Permission Control Vulnerability

Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49307 — Multi-mode Input Module Access Control Bypass

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
3.3 LOW
CVE-2026-49306 — Linux Kernel Time and Time Zone Module Use-After-Free Vulnerability

UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49305 — Wi-Fi Enhancement Module Improper Authorization Vulnerability

Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49304 — Device Key Management Module Improper Authorization Vulnerability

Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.1 MEDIUM
CVE-2026-49303 — Notification Module Improper Authorization Vulnerability

Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49302 — Notification Service Improper Authorization

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49301 — Gallery Module Improper Authorization

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

emui harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-20000 — itsourcecode Hospital Management System viewprescriptionrecord.php sql injection

A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the argument deli…

hospital_management_system | Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11149 Results