Search
100 CVEs · published 2026-08-30 to 2026-08-30
CVEs (100)
Showing 1–25 of 100
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-82417 | MEDIUM | Patched | 5.3 | 2026-08-30 | ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuff… |
| CVE-2026-75847 | NONE | Patched | — | 2026-08-30 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the… |
| CVE-2026-77831 | NONE | Patched | — | 2026-08-30 | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update act… |
| CVE-2026-77970 | NONE | Patched | — | 2026-08-30 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sen… |
| CVE-2026-82562 | LOW | Patched | 3.7 | 2026-08-30 | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into… |
| CVE-2026-75759 | NONE | Patched | — | 2026-08-30 | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token … |
| CVE-2026-77846 | NONE | Patched | — | 2026-08-30 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse int… |
| CVE-2026-15980 | CRITICAL | 9.8 | 2026-08-30 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_li… | |
| CVE-2026-82478 | HIGH | 7.3 | 2026-08-30 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVaria… | |
| CVE-2026-82479 | MEDIUM | 6.3 | 2026-08-30 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Modu… | |
| CVE-2026-82480 | HIGH | 7.4 | 2026-08-30 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb… | |
| CVE-2026-14307 | NONE | Patched | — | 2026-08-30 | The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML… |
| CVE-2026-14835 | NONE | — | 2026-08-30 | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post me… | |
| CVE-2026-19722 | NONE | Patched | — | 2026-08-30 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, all… |
| CVE-2026-76585 | NONE | Patched | — | 2026-08-30 | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which c… |
| CVE-2026-78364 | NONE | Patched | — | 2026-08-30 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allo… |
| CVE-2026-81660 | NONE | Patched | — | 2026-08-30 | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields bef… |
| CVE-2026-81766 | NONE | Patched | — | 2026-08-30 | The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before in… |
| CVE-2026-82482 | LOW | 3.5 | 2026-08-30 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the comp… | |
| CVE-2026-82483 | LOW | 3.5 | 2026-08-30 | A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden … | |
| CVE-2026-82484 | MEDIUM | 6.3 | 2026-08-30 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argumen… | |
| CVE-2026-82485 | MEDIUM | 6.3 | 2026-08-30 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. S… | |
| CVE-2026-82486 | MEDIUM | 5.0 | 2026-08-30 | A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipul… | |
| CVE-2026-82487 | MEDIUM | 6.3 | 2026-08-30 | A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be ex… | |
| CVE-2026-82488 | LOW | 3.5 | 2026-08-30 | A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument User… |