Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

100 CVEs · published 2026-08-30 to 2026-08-30

CVEs (100)

Showing 51–75 of 100

CVE ID Severity Patch CVSS Published Description
CVE-2026-82547 MEDIUM 6.5 2026-08-30 A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Compl…
CVE-2026-82545 MEDIUM 6.3 2026-08-30 A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the…
CVE-2026-82642 HIGH 8.8 2026-08-30 Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only …
CVE-2026-82641 HIGH 8.6 2026-08-30 keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and …
CVE-2026-82640 MEDIUM 5.5 2026-08-30 browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to …
CVE-2026-82639 HIGH 7.5 2026-08-30 NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API …
CVE-2026-82638 HIGH 7.5 2026-08-30 jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can…
CVE-2026-82637 MEDIUM 5.3 2026-08-30 browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations b…
CVE-2026-82636 HIGH 7.9 2026-08-30 Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library…
CVE-2026-82544 MEDIUM 4.3 2026-08-30 A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Passwo…
CVE-2026-82635 HIGH Patched 8.8 2026-08-30 Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containin…
CVE-2026-82634 MEDIUM 6.5 2026-08-30 Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates…
CVE-2026-82633 MEDIUM Patched 4.3 2026-08-30 Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve g…
CVE-2026-82543 HIGH 7.3 2026-08-30 A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pick…
CVE-2026-82542 CRITICAL 10.0 2026-08-30 A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component B…
CVE-2026-82541 MEDIUM 6.3 2026-08-30 A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.p…
CVE-2026-82540 MEDIUM 6.3 2026-08-30 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of th…
CVE-2026-81318 NONE Patched — 2026-08-30 Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another ten…
CVE-2026-81316 NONE Patched — 2026-08-30 Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded…
CVE-2026-80227 NONE Patched — 2026-08-30 Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed…
CVE-2026-78691 NONE Patched — 2026-08-30 Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_w…
CVE-2026-78228 NONE Patched — 2026-08-30 Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and …
CVE-2026-78038 NONE Patched — 2026-08-30 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of A…
CVE-2026-77454 NONE Patched — 2026-08-30 Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that decl…
CVE-2026-82539 CRITICAL 9.1 2026-08-30 A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. …