Search
100 CVEs · published 2026-08-30 to 2026-08-30
CVEs (100)
Showing 1–25 of 100
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82542 | CRITICAL | 10.0 | 2026-08-30 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component B… | |
| CVE-2026-82592 | CRITICAL | 9.9 | 2026-08-30 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endp… | |
| CVE-2026-15980 | CRITICAL | 9.8 | 2026-08-30 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_li… | |
| CVE-2026-82539 | CRITICAL | 9.1 | 2026-08-30 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. … | |
| CVE-2026-82653 | HIGH | 8.9 | 2026-08-30 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into… | |
| CVE-2026-82654 | HIGH | 8.9 | 2026-08-30 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to … | |
| CVE-2026-82642 | HIGH | 8.8 | 2026-08-30 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only … | |
| CVE-2026-82635 | HIGH | Patched | 8.8 | 2026-08-30 | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containin… |
| CVE-2026-81636 | NONE | Patched | — | 2026-08-30 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-comple… |
| CVE-2026-82645 | HIGH | 8.6 | 2026-08-30 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' reque… | |
| CVE-2026-82641 | HIGH | 8.6 | 2026-08-30 | keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and … | |
| CVE-2026-82549 | HIGH | 8.3 | 2026-08-30 | A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to i… | |
| CVE-2026-82636 | HIGH | 7.9 | 2026-08-30 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library… | |
| CVE-2026-75759 | NONE | Patched | — | 2026-08-30 | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token … |
| CVE-2026-56718 | HIGH | 7.5 | 2026-08-30 | AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to… | |
| CVE-2026-82655 | HIGH | Patched | 7.5 | 2026-08-30 | Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute ar… |
| CVE-2026-82657 | HIGH | Patched | 7.5 | 2026-08-30 | Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve foru… |
| CVE-2026-82644 | HIGH | 7.5 | 2026-08-30 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The fun… | |
| CVE-2026-82638 | HIGH | 7.5 | 2026-08-30 | jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can… | |
| CVE-2026-82639 | HIGH | 7.5 | 2026-08-30 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API … | |
| CVE-2026-82480 | HIGH | 7.4 | 2026-08-30 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb… | |
| CVE-2026-82543 | HIGH | 7.3 | 2026-08-30 | A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pick… | |
| CVE-2026-82478 | HIGH | 7.3 | 2026-08-30 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVaria… | |
| CVE-2026-78699 | NONE | Patched | — | 2026-08-30 | Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to hav… |
| CVE-2026-80223 | NONE | Patched | — | 2026-08-30 | Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscript… |