Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

100 CVEs · published 2026-08-30 to 2026-08-30

CVEs (100)

Showing 26–50 of 100

CVE ID Severity Patch CVSS Published Description
CVE-2026-81322 NONE Patched — 2026-08-30 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or an…
CVE-2026-81319 NONE Patched — 2026-08-30 Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by tr…
CVE-2026-82553 MEDIUM 6.3 2026-08-30 A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of t…
CVE-2026-82552 MEDIUM 4.3 2026-08-30 A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of …
CVE-2026-82551 MEDIUM 5.3 2026-08-30 A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing …
CVE-2026-82550 MEDIUM 5.3 2026-08-30 A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of …
CVE-2026-82549 HIGH 8.3 2026-08-30 A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to i…
CVE-2026-78699 NONE Patched — 2026-08-30 Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to hav…
CVE-2026-82658 MEDIUM Patched 4.3 2026-08-30 Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's fu…
CVE-2026-82657 HIGH Patched 7.5 2026-08-30 Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve foru…
CVE-2026-82656 LOW Patched 2.6 2026-08-30 Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path travers…
CVE-2026-82655 HIGH Patched 7.5 2026-08-30 Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute ar…
CVE-2026-82654 HIGH 8.9 2026-08-30 SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to …
CVE-2026-82653 HIGH 8.9 2026-08-30 SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into…
CVE-2026-82652 MEDIUM 5.3 2026-08-30 SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can …
CVE-2026-82651 MEDIUM 4.9 2026-08-30 SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/s…
CVE-2026-82650 MEDIUM Patched 4.4 2026-08-30 SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/templa…
CVE-2026-82649 NONE — 2026-08-30 SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes …
CVE-2026-82648 HIGH 7.1 2026-08-30 WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal …
CVE-2026-82647 MEDIUM 6.1 2026-08-30 WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address …
CVE-2026-82646 MEDIUM 6.1 2026-08-30 WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by…
CVE-2026-82645 HIGH 8.6 2026-08-30 AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' reque…
CVE-2026-82644 HIGH 7.5 2026-08-30 WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The fun…
CVE-2026-82643 MEDIUM 6.5 2026-08-30 WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting…
CVE-2026-82548 MEDIUM 5.3 2026-08-30 A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation cau…