Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-61373 UNKNOWN — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … Oct 02, 2026
CVE-2026-104609 HIGH 7.3 A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument … Oct 02, 2026
CVE-2026-104473 MEDIUM 6.1 YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanitized parameters such as incomingurl, id, file, tags, … Oct 02, 2026
CVE-2026-104472 HIGH 7.5 YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request … Oct 02, 2026
CVE-2026-104471 HIGH 7.2 YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV … Oct 02, 2026
CVE-2026-104470 HIGH 7.4 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. … Oct 02, 2026
CVE-2026-104469 MEDIUM 6.8 YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers … Oct 02, 2026
CVE-2026-104468 MEDIUM 4.8 YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who … Oct 02, 2026
CVE-2026-104467 HIGH 8.1 YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. … Oct 02, 2026
CVE-2026-104466 MEDIUM 5.4 YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers … Oct 02, 2026
CVE-2026-104465 MEDIUM 6.1 YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field parameter of the mail handler. Attackers … Oct 02, 2026
CVE-2026-104464 HIGH 8.6 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to … Oct 02, 2026
CVE-2026-104463 HIGH 7.0 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public … Oct 02, 2026
CVE-2026-104462 HIGH 7.5 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. … Oct 02, 2026
CVE-2026-104461 MEDIUM 5.4 YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so … Oct 02, 2026
CVE-2026-104460 HIGH 7.5 YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in … Oct 02, 2026
CVE-2026-104459 MEDIUM 6.5 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST … Oct 02, 2026
CVE-2026-104458 MEDIUM 6.5 YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible … Oct 02, 2026
CVE-2026-104457 HIGH 8.6 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into … Oct 02, 2026
CVE-2026-104456 HIGH 7.6 YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can … Oct 02, 2026
CVE-2026-104455 MEDIUM 5.3 YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can … Oct 02, 2026
CVE-2026-104454 MEDIUM 5.3 YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small … Oct 02, 2026
CVE-2026-104453 MEDIUM 5.4 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted … Oct 02, 2026
CVE-2026-104452 MEDIUM 5.4 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF … Oct 02, 2026
CVE-2026-104451 MEDIUM 4.3 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token … Oct 02, 2026