Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

18 CVEs · published 2026-08-30 to 2026-08-30, High severity

CVEs (18)

Showing 1–18 of 18

CVE ID Severity Patch CVSS Published Description
CVE-2026-56718 HIGH 7.5 2026-08-30 AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to…
CVE-2026-82549 HIGH 8.3 2026-08-30 A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to i…
CVE-2026-82657 HIGH Patched 7.5 2026-08-30 Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve foru…
CVE-2026-82655 HIGH Patched 7.5 2026-08-30 Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute ar…
CVE-2026-82654 HIGH 8.9 2026-08-30 SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to …
CVE-2026-82653 HIGH 8.9 2026-08-30 SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into…
CVE-2026-82648 HIGH 7.1 2026-08-30 WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal …
CVE-2026-82645 HIGH 8.6 2026-08-30 AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' reque…
CVE-2026-82644 HIGH 7.5 2026-08-30 WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The fun…
CVE-2026-82642 HIGH 8.8 2026-08-30 Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only …
CVE-2026-82641 HIGH 8.6 2026-08-30 keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and …
CVE-2026-82639 HIGH 7.5 2026-08-30 NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API …
CVE-2026-82638 HIGH 7.5 2026-08-30 jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can…
CVE-2026-82636 HIGH 7.9 2026-08-30 Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library…
CVE-2026-82635 HIGH Patched 8.8 2026-08-30 Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containin…
CVE-2026-82543 HIGH 7.3 2026-08-30 A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pick…
CVE-2026-82480 HIGH 7.4 2026-08-30 A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb…
CVE-2026-82478 HIGH 7.3 2026-08-30 A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVaria…