[vulnfeed] 10 critical CVEs — 2026-08-16 00:00 UTC
vulnfeed
Critical alert — 2026-08-16 02:01 UTC
10 new critical CVEs
in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-74764CRITICAL
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tar
CVSS 10.0
CVE-2026-73041CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnot
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute
CVSS 9.4
CVE-2026-73042CRITICAL
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored va
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inj
CVSS 9.4
CVE-2026-73043CRITICAL
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operat
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitizati
CVSS 9.4
CVE-2026-73044CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads throug
CVSS 9.4
CVE-2026-73050CRITICAL
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, all
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inje
CVSS 9.4
CVE-2026-73052CRITICAL
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly in
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming
CVSS 9.4
CVE-2026-73053CRITICAL
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-enc
CVSS 9.4
CVE-2026-73046CRITICAL
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts
CVSS 9.3
CVE-2026-73055CRITICAL
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment co
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/s
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: