[vulnfeed] 3 critical CVEs — 2026-08-30 16:00 UTC
vulnfeed
Critical alert — 2026-08-30 19:22 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-82653CRITICAL
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped p
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Atta
CVSS 9.3
CVE-2026-82654CRITICAL
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadc
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags tha
CVSS 9.3
CVE-2026-82645CRITICAL
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_res
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: