6.2 CVE-2026-49301
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this...

2026-08-17T11:16:38.830

6.2 CVE-2026-49302
Permission control vulnerability in the notification service module. Impact: Successful exploitation...

2026-08-17T09:17:30.130

5.1 CVE-2026-49303
Permission control vulnerability in the notification module. Impact: Successful exploitation of...

2026-08-17T09:17:30.270

6.2 CVE-2026-49304
Permission control vulnerability in the device key management module. Impact: Successful exploitation...

2026-08-17T12:18:50.200

6.2 CVE-2026-49305
Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation...

2026-08-17T11:16:38.933

3.3 CVE-2026-49306
UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability...

2026-08-17T11:16:39.030

6.2 CVE-2026-49307
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation...

2026-08-17T16:16:56.917

5.5 CVE-2026-49308
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this...

2026-08-17T11:16:39.130

4 CVE-2026-58560
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this...

2026-08-17T15:16:56.190

4 CVE-2026-58561
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this...

2026-08-17T12:18:56.143

8.8 CVE-2026-74845
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability,...

2026-08-17T11:16:40.780

8.7 CVE-2026-74798
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool....

2026-08-17T11:16:39.873

9.3 CVE-2026-74799
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without...

2026-08-17T15:16:58.120

9 CVE-2026-74800
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving...

2026-08-17T16:17:49.060

8.2 CVE-2026-74801
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line...

2026-08-17T16:17:49.183

8.2 CVE-2026-74802
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only...

2026-08-17T18:18:15.367

6.3 CVE-2026-74842
A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452....

2026-08-17T11:16:40.597

4.2 CVE-2026-74867
SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie...

2026-08-17T11:16:40.897

7.5 CVE-2026-74868
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service...

2026-08-17T15:16:58.353

7.7 CVE-2026-74869
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler...

2026-08-17T16:17:49.473

3.3 CVE-2026-74870
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm...

2026-08-17T16:17:49.597