Common Vulnerabilities and Exposures (CVE)

CVE-2026-77875

Sep 18, 2026 23:29:28 UTC

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB ...

CVE-2026-93923

Sep 18, 2026 23:12:09 UTC

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious s...

CVE-2026-93922

Sep 18, 2026 23:12:08 UTC

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute...

CVE-2026-93921

Sep 18, 2026 23:12:07 UTC

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read block...

CVE-2026-92768

Sep 18, 2026 22:37:40 UTC

A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or install...

CVE-2026-92747

Sep 18, 2026 22:37:35 UTC

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occ...

CVE-2026-91205

Sep 18, 2026 22:37:30 UTC

A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory wi...

CVE-2026-91203

Sep 18, 2026 22:37:29 UTC

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating di...

CVE-2026-75885

Sep 18, 2026 21:58:11 UTC

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), w...

CVE-2026-93740

Sep 18, 2026 21:45:12 UTC

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate...

CVE-2026-93739

Sep 18, 2026 21:15:07 UTC

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be perfor...

CVE-2026-93738

Sep 18, 2026 21:00:10 UTC

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible t...

CVE-2026-85887

Sep 18, 2026 20:47:11 UTC

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

CVE-2026-83946

Sep 18, 2026 20:47:11 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-69843

Sep 18, 2026 20:47:10 UTC

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.