5.3

CVSS3.1

CVE-2026-23849 - File Browser vulnerable to Username Enumeration via Timing Attack in /api/login

File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, and edit files. Prior to version 2.55.0, the JSONAuth. Auth function contains a logic flaw that allows unauthenticated attackers to enumerate valid usernames by measuring…

πŸ“… Published: Jan. 19, 2026, 8:37 p.m. πŸ”„ Last Modified: April 18, 2026, 5 a.m.

6.5

CVSS3.1

CVE-2026-23848 - MyTube has Rate Limiting Bypass via X-Forwarded-For Header Spoofing

MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via `X-Forwarded-For` header spoofing allows unauthenticated attackers to bypass IP-based rate limiting on general API endpoints. Attackers can spoof client IPs by manipulating …

πŸ“… Published: Jan. 19, 2026, 8:34 p.m. πŸ”„ Last Modified: April 18, 2026, 5 a.m.

6.9

CVSS4.0

CVE-2026-1175 - birkir prime GraphQL Directive graphql information exposure

A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Directive Handler. Such manipulation leads to information exposure through error message. The attack may be performed from remote. The exploit is publicl…

πŸ“… Published: Jan. 19, 2026, 8:32 p.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

9.8

CVSS3.1

CVE-2026-23837 - MyTube has an Authorization Bypass vulnerability

MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMiddleware. By simply not providing an authentication co…

πŸ“… Published: Jan. 19, 2026, 8:09 p.m. πŸ”„ Last Modified: April 18, 2026, 5 a.m.

6.9

CVSS4.0

CVE-2026-1174 - birkir prime GraphQL Alias graphql resource consumption

A vulnerability was determined in birkir prime up to 0.4.0.beta.0. This affects an unknown function of the file /graphql of the component GraphQL Alias Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. The exploit has been publicly disclosed …

πŸ“… Published: Jan. 19, 2026, 8:02 p.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

5.8

CVSS4.0

CVE-2026-23852 - SiYuan vulnerable to Stored XSS / RCE via `setBlockAttrs` icon attribute

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBlockAttrs` API. The payload is later rendered in t…

πŸ“… Published: Jan. 19, 2026, 8 p.m. πŸ”„ Last Modified: April 18, 2026, 5 a.m.

8.3

CVSS4.0

CVE-2026-23851 - SiYuan Vulnerable to Arbitrary File Read via File Copy Functionality

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. The function allows authenticated users to copy files from any location on the server's filesystem into the application's workspace without proper path …

πŸ“… Published: Jan. 19, 2026, 7:57 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

7.8

CVSS4.0

CVE-2026-23850 - SiYuan vulnerable to arbitrary file read

SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue.

πŸ“… Published: Jan. 19, 2026, 7:52 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

2.1

CVSS4.0

CVE-2026-23847 - SiYuan Vulnerable to Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIcon due to unsanitized SVG input. The endpoint generates SVG images for text icons (type=8). The content query parameter is inserted directly into the S…

πŸ“… Published: Jan. 19, 2026, 7:46 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

8.1

CVSS3.1

CVE-2026-23846 - Tugtainer vulnerable to Password Exposure via URL Query Parameter

Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially expo…

πŸ“… Published: Jan. 19, 2026, 7:42 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.
Total resulsts: 349182
Page 2072 of 34,919
Β« previous page Β» next page
Filters