Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82628 | HIGH | 8.8 | A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a … | Aug 31, 2026 |
| CVE-2026-82625 | MEDIUM | 4.3 | A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. … | Aug 31, 2026 |
| CVE-2026-82624 | MEDIUM | 5.3 | A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the … | Aug 31, 2026 |
| CVE-2026-82623 | MEDIUM | 5.3 | A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History … | Aug 31, 2026 |
| CVE-2026-82622 | LOW | 3.5 | A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component … | Aug 31, 2026 |
| CVE-2026-77013 | MEDIUM | 5.3 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check … | Aug 31, 2026 |
| CVE-2026-68951 | MEDIUM | 5.3 | GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data. | Aug 31, 2026 |
| CVE-2026-58574 | CRITICAL | 9.8 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this … | Aug 31, 2026 |
| CVE-2026-53620 | MEDIUM | 6.3 | GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could … | Aug 31, 2026 |
| CVE-2026-40465 | MEDIUM | 5.3 | NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter. | Aug 31, 2026 |
| CVE-2026-40464 | MEDIUM | 5.4 | NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access … | Aug 31, 2026 |
| CVE-2026-40463 | HIGH | 7.6 | WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load … | Aug 31, 2026 |
| CVE-2026-82621 | HIGH | 7.3 | A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component … | Aug 31, 2026 |
| CVE-2026-82620 | MEDIUM | 6.3 | A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a … | Aug 31, 2026 |
| CVE-2026-82619 | MEDIUM | 4.3 | A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impacted element is the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/subscription_mgr.c. Such manipulation of the … | Aug 31, 2026 |
| CVE-2026-82618 | MEDIUM | 4.3 | A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String … | Aug 31, 2026 |
| CVE-2026-82616 | CRITICAL | 9.9 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in … | Aug 31, 2026 |
| CVE-2026-82615 | HIGH | 7.3 | A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component … | Aug 31, 2026 |
| CVE-2026-82614 | HIGH | 7.3 | A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.php?q=product of the component … | Aug 31, 2026 |
| CVE-2026-82727 | UNKNOWN | — | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted … | Aug 31, 2026 |
| CVE-2026-82726 | UNKNOWN | — | Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a … | Aug 31, 2026 |
| CVE-2026-82725 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, … | Aug 31, 2026 |
| CVE-2026-82724 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are … | Aug 31, 2026 |
| CVE-2026-82613 | HIGH | 7.3 | A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search … | Aug 31, 2026 |
| CVE-2026-82612 | HIGH | 7.3 | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item … | Aug 31, 2026 |