Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34617
Total
2726
Critical
10244
High
10450
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75831 | HIGH | 7.6 | Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is … | Aug 18, 2026 |
| CVE-2026-75830 | HIGH | 7.1 | grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled … | Aug 18, 2026 |
| CVE-2026-75829 | HIGH | 8.1 | grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers … | Aug 18, 2026 |
| CVE-2026-75828 | HIGH | 8.7 | Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors … | Aug 18, 2026 |
| CVE-2026-75827 | HIGH | 8.8 | Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. … | Aug 18, 2026 |
| CVE-2026-75774 | LOW | 3.7 | A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth … | Aug 18, 2026 |
| CVE-2026-75107 | MEDIUM | 5.4 | Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers … | Aug 18, 2026 |
| CVE-2026-74908 | MEDIUM | 4.6 | Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files … | Aug 18, 2026 |
| CVE-2026-74907 | MEDIUM | 5.9 | Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated … | Aug 18, 2026 |
| CVE-2026-74906 | HIGH | 7.5 | SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the visibility list instead of the disabled list. … | Aug 18, 2026 |
| CVE-2026-74905 | HIGH | 7.1 | SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDialer to enforce SSRF protection in SafeMode. … | Aug 18, 2026 |
| CVE-2026-74904 | HIGH | 7.5 | SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by … | Aug 18, 2026 |
| CVE-2026-74903 | MEDIUM | 4.3 | SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which is guarded only by CheckAuth middleware instead of CheckAdminRole like its … | Aug 18, 2026 |
| CVE-2026-74902 | HIGH | 8.6 | SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via … | Aug 18, 2026 |
| CVE-2026-5224 | MEDIUM | 5.7 | Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: … | Aug 18, 2026 |
| CVE-2026-15585 | HIGH | 7.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP … | Aug 18, 2026 |
| CVE-2026-75773 | LOW | 3.7 | A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login … | Aug 18, 2026 |
| CVE-2026-75627 | CRITICAL | 9.8 | Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path … | Aug 18, 2026 |
| CVE-2026-75626 | CRITICAL | 9.3 | SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event … | Aug 18, 2026 |
| CVE-2026-19608 | MEDIUM | 5.3 | A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue … | Aug 18, 2026 |
| CVE-2026-19447 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOrbis: … | Aug 18, 2026 |
| CVE-2024-14046 | MEDIUM | 6.3 | A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document … | Aug 18, 2026 |
| CVE-2026-18929 | UNKNOWN | — | Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip … | Aug 18, 2026 |
| CVE-2026-43971 | UNKNOWN | — | Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates … | Aug 18, 2026 |
| CVE-2024-14045 | MEDIUM | 6.3 | A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit … | Aug 18, 2026 |