NVD disclosure day

Published threat advisories for August 30, 2026

CVE advisoryCRITICAL

CVE-2026-82654

SiYuan Block Name Cross-Site Scripting Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

SiYuan improperly escapes fields, allowing attackers to inject script tags into block names. When users view documents referencing these blocks, the scripts execute, potentially leading to cross-site scripting attacks and unauthorized information disclosure. This is a concern if SiYuan is deployed within your environme

CVE advisoryCRITICAL

CVE-2026-82653

SiYuan Stored XSS in confirmDialog Via Package and Notebook Names.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

SiYuan contains a stored cross-site scripting vulnerability where unescaped names are directly inserted into web content. This could allow an attacker to execute malicious scripts in a user's browser when they interact with packages or notebooks. The primary concern is understanding the reach and impact of this vulnera

CVE advisoryCRITICAL

CVE-2026-82645

AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

AVideo is affected by a vulnerability that allows unauthenticated attackers to disclose stream credentials for external platforms like YouTube and Facebook. By forging a token, attackers can bypass access controls and obtain sensitive stream keys and URLs. This could lead to unauthorized use of streaming services. The

CVE advisoryCRITICAL

CVE-2026-82542

Tenda HG10 Buffer Overflow Via Boa Web Server

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical buffer overflow vulnerability exists in the Boa Web Server component of Tenda devices, specifically within the IPv6 routing function. Attackers can exploit this remotely and without authentication to manipulate system data, potentially leading to a complete device compromise. The network-facing nature of the

CVE advisoryCRITICAL

CVE-2026-15980

MyHome Core WordPress Plugin Authentication Bypass Leading to Account Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the MyHome Core WordPress plugin that allows unauthenticated attackers to bypass authentication. If specific theme configurations are met, attackers can obtain valid authentication cookies for user accounts, potentially including administrators. This could lead to unauthorized access and contr