Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104450 | MEDIUM | 6.5 | YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. … | Oct 02, 2026 |
| CVE-2026-104449 | MEDIUM | 6.5 | YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via … | Oct 02, 2026 |
| CVE-2026-104448 | HIGH | 8.1 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback … | Oct 02, 2026 |
| CVE-2026-104447 | HIGH | 7.1 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers … | Oct 02, 2026 |
| CVE-2026-104446 | MEDIUM | 6.5 | YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. … | Oct 02, 2026 |
| CVE-2026-104445 | HIGH | 8.2 | YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. … | Oct 02, 2026 |
| CVE-2026-104444 | HIGH | 7.1 | YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments … | Oct 02, 2026 |
| CVE-2026-104443 | HIGH | 8.1 | YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples … | Oct 02, 2026 |
| CVE-2026-104442 | MEDIUM | 5.8 | YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication … | Oct 02, 2026 |
| CVE-2026-104441 | MEDIUM | 5.3 | YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the … | Oct 02, 2026 |
| CVE-2026-104440 | MEDIUM | 5.3 | YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. … | Oct 02, 2026 |
| CVE-2026-104439 | MEDIUM | 5.3 | YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit … | Oct 02, 2026 |
| CVE-2026-104438 | MEDIUM | 5.3 | YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. … | Oct 02, 2026 |
| CVE-2026-104437 | HIGH | 7.4 | Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of … | Oct 02, 2026 |
| CVE-2026-104436 | LOW | 3.7 | Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers … | Oct 02, 2026 |
| CVE-2026-104435 | HIGH | 7.4 | Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. … | Oct 02, 2026 |
| CVE-2026-104434 | MEDIUM | 6.5 | ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing … | Oct 02, 2026 |
| CVE-2026-104432 | MEDIUM | 5.3 | Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the … | Oct 02, 2026 |
| CVE-2026-104431 | HIGH | 7.5 | Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script … | Oct 02, 2026 |
| CVE-2026-104430 | HIGH | 7.5 | Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by … | Oct 02, 2026 |
| CVE-2026-104429 | MEDIUM | 5.3 | Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued … | Oct 02, 2026 |
| CVE-2026-104428 | MEDIUM | 5.3 | The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the … | Oct 02, 2026 |
| CVE-2026-104427 | MEDIUM | 5.9 | Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. … | Oct 02, 2026 |
| CVE-2026-104426 | MEDIUM | 5.9 | Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can … | Oct 02, 2026 |
| CVE-2026-104425 | MEDIUM | 5.3 | ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without … | Oct 02, 2026 |