Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61373 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-104609 | HIGH | 7.3 | A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument … | Oct 02, 2026 |
| CVE-2026-104473 | MEDIUM | 6.1 | YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanitized parameters such as incomingurl, id, file, tags, … | Oct 02, 2026 |
| CVE-2026-104472 | HIGH | 7.5 | YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request … | Oct 02, 2026 |
| CVE-2026-104471 | HIGH | 7.2 | YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV … | Oct 02, 2026 |
| CVE-2026-104470 | HIGH | 7.4 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. … | Oct 02, 2026 |
| CVE-2026-104469 | MEDIUM | 6.8 | YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers … | Oct 02, 2026 |
| CVE-2026-104468 | MEDIUM | 4.8 | YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who … | Oct 02, 2026 |
| CVE-2026-104467 | HIGH | 8.1 | YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. … | Oct 02, 2026 |
| CVE-2026-104466 | MEDIUM | 5.4 | YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers … | Oct 02, 2026 |
| CVE-2026-104465 | MEDIUM | 6.1 | YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field parameter of the mail handler. Attackers … | Oct 02, 2026 |
| CVE-2026-104464 | HIGH | 8.6 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to … | Oct 02, 2026 |
| CVE-2026-104463 | HIGH | 7.0 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public … | Oct 02, 2026 |
| CVE-2026-104462 | HIGH | 7.5 | YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. … | Oct 02, 2026 |
| CVE-2026-104461 | MEDIUM | 5.4 | YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so … | Oct 02, 2026 |
| CVE-2026-104460 | HIGH | 7.5 | YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in … | Oct 02, 2026 |
| CVE-2026-104459 | MEDIUM | 6.5 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST … | Oct 02, 2026 |
| CVE-2026-104458 | MEDIUM | 6.5 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible … | Oct 02, 2026 |
| CVE-2026-104457 | HIGH | 8.6 | YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into … | Oct 02, 2026 |
| CVE-2026-104456 | HIGH | 7.6 | YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can … | Oct 02, 2026 |
| CVE-2026-104455 | MEDIUM | 5.3 | YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can … | Oct 02, 2026 |
| CVE-2026-104454 | MEDIUM | 5.3 | YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small … | Oct 02, 2026 |
| CVE-2026-104453 | MEDIUM | 5.4 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted … | Oct 02, 2026 |
| CVE-2026-104452 | MEDIUM | 5.4 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF … | Oct 02, 2026 |
| CVE-2026-104451 | MEDIUM | 4.3 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token … | Oct 02, 2026 |