Latest CVE

Latest Vulnerabilities

  • CVE-2026-82550 - Linux Foundation Magma NGSetupRequest input validation

    CVE ID :CVE-2026-82550
    Published : Aug. 30, 2026, 3:45 p.m. | 16 minutes ago
    Description :A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82549 - Linux Foundation Magma SecurityModeComplete integrity check

    CVE ID :CVE-2026-82549
    Published : Aug. 30, 2026, 3:30 p.m. | 31 minutes ago
    Description :A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82658 - Admidio before 5.0.12 Broken Access Control via profile_function.php

    CVE ID :CVE-2026-82658
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.
    Severity: 5.3 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82657 - Admidio before 5.0.12 Authentication Bypass via RSS feeds

    CVE ID :CVE-2026-82657
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.
    Severity: 8.7 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82656 - Admidio before 5.0.12 Path Traversal via Photo ZIP Download

    CVE ID :CVE-2026-82656
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious album names containing directory traversal sequences that escape the intended directory when recipients extract the archive, potentially writing files outside the target directory.
    Severity: 2.6 | LOW
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82655 - Admidio before 5.0.12 SQL Injection via relation_type_list

    CVE ID :CVE-2026-82655
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.
    Severity: 8.7 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82654 - SiYuan before v3.8.1 Stored XSS via block name

    CVE ID :CVE-2026-82654
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
    Severity: 9.3 | CRITICAL
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82653 - SiYuan before v3.8.1 Stored XSS via confirmDialog

    CVE ID :CVE-2026-82653
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.
    Severity: 9.3 | CRITICAL
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82652 - SiYuan before v3.8.1 Information Disclosure via Publish Access

    CVE ID :CVE-2026-82652
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.
    Severity: 6.9 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-82651 - SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff

    CVE ID :CVE-2026-82651
    Published : Aug. 30, 2026, 3:16 p.m. | 45 minutes ago
    Description :SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticated administrator can retrieve historical snapshots of sensitive files that the guard is meant to block, including data/.siyuan/publishAccess.json (plaintext publish-mode passwords) and files under data/templates/.
    Severity: 6.9 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
| Date published: Sun, 30 Aug 2026 15:45:09 +0000
Back to newsfeed list