Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-69085 — SiYuan before v3.7.3 SQL Injection via searchDocs

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no …

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 CRITICAL
CVE-2026-69084 — SiYuan before v3.7.3 SQL Injection via searchEmbedBlock

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, rea…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 CRITICAL
CVE-2026-69083 — SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute …

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-68587 — SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return ren…

Remote | Information Disclosure
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-68586 — SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the correspond…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.8 MEDIUM
CVE-2026-68585 — SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents w…

Remote | Information Disclosure
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-68584 — SiYuan before v3.7.3 Authentication Bypass via Content Endpoints

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perfor…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.2 HIGH
CVE-2026-67608 — Telenia TVox 26.5.3 OS Command Injection via action_audio.php

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to exe…

tvox | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.8 CRITICAL
CVE-2026-64827 — Telenia TVox 26.5.3 Authentication Bypass via set_env.php

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAcce…

tvox | Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.8 HIGH
CVE-2026-18642 — Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-otp-lock

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 HIGH
CVE-2026-18601 — GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injec…

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a man…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.0 HIGH
CVE-2026-18600 — GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Networ…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-18108 — Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encr…

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-18092 — Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signatu…

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtr…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-18089 — Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying re…

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xm…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
4.8 MEDIUM
CVE-2026-56609 — HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026…

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack moder…

Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
3.7 LOW
CVE-2026-56608 — HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026…

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionaliti…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.8 CRITICAL
CVE-2026-2346 — IDOR in Menulux Software's Mobile App

Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.0 HIGH
CVE-2026-18599 — GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. Thi…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.0 HIGH
CVE-2026-18598 — GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC …

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9319 Results