CVE ID :CVE-2026-93923 Published : Sept. 18, 2026, 11:12 p.m. | 28 minutes ago Description :SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored…
CVE-2026-93922 – SiYuan through 3.8.4 Stored XSS via notebook names
CVE ID :CVE-2026-93922 Published : Sept. 18, 2026, 11:12 p.m. | 28 minutes ago Description :SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing…
CVE-2026-93740 – Totolink A3002MU formWlEncrypt buffer overflow
CVE ID :CVE-2026-93740 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt….
CVE-2026-93739 – Totolink A3002MU formWlAc buffer overflow
CVE ID :CVE-2026-93739 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc….
CVE-2026-75885 – Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint
CVE ID :CVE-2026-75885 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows…
CVE-2026-79954 – NASA CryptoLib 1.5.0 – TC receive path accepts Security Associations from the wrong GVCID
CVE ID :CVE-2026-79954 Published : Sept. 18, 2026, 1:16 a.m. | 18 minutes ago Description :NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the…
CVE-2026-93453 – SOGo before 5.12.11 Password Reset Token Interception via Origin Header
CVE ID :CVE-2026-93453 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers…
CVE-2026-93452 – snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress
CVE ID :CVE-2026-93452 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of…
CVE-2026-93450 – go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal
CVE ID :CVE-2026-93450 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to…
CVE-2026-85878 – Azure Database for PostgreSQL Elevation of Privilege Vulnerability
CVE ID :CVE-2026-85878 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network….