Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42239
Total
3441
Critical
12474
High
12431
Medium
CVE ID Severity Score Description Published
CVE-2026-82628 HIGH 8.8 A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a … Aug 31, 2026
CVE-2026-82625 MEDIUM 4.3 A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. … Aug 31, 2026
CVE-2026-82624 MEDIUM 5.3 A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the … Aug 31, 2026
CVE-2026-82623 MEDIUM 5.3 A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History … Aug 31, 2026
CVE-2026-82622 LOW 3.5 A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component … Aug 31, 2026
CVE-2026-77013 MEDIUM 5.3 The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check … Aug 31, 2026
CVE-2026-68951 MEDIUM 5.3 GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data. Aug 31, 2026
CVE-2026-58574 CRITICAL 9.8 Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this … Aug 31, 2026
CVE-2026-53620 MEDIUM 6.3 GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could … Aug 31, 2026
CVE-2026-40465 MEDIUM 5.3 NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter. Aug 31, 2026
CVE-2026-40464 MEDIUM 5.4 NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access … Aug 31, 2026
CVE-2026-40463 HIGH 7.6 WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load … Aug 31, 2026
CVE-2026-82621 HIGH 7.3 A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component … Aug 31, 2026
CVE-2026-82620 MEDIUM 6.3 A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a … Aug 31, 2026
CVE-2026-82619 MEDIUM 4.3 A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impacted element is the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/subscription_mgr.c. Such manipulation of the … Aug 31, 2026
CVE-2026-82618 MEDIUM 4.3 A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String … Aug 31, 2026
CVE-2026-82616 CRITICAL 9.9 A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in … Aug 31, 2026
CVE-2026-82615 HIGH 7.3 A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component … Aug 31, 2026
CVE-2026-82614 HIGH 7.3 A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.php?q=product of the component … Aug 31, 2026
CVE-2026-82727 UNKNOWN Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted … Aug 31, 2026
CVE-2026-82726 UNKNOWN Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a … Aug 31, 2026
CVE-2026-82725 UNKNOWN Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, … Aug 31, 2026
CVE-2026-82724 UNKNOWN Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are … Aug 31, 2026
CVE-2026-82613 HIGH 7.3 A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search … Aug 31, 2026
CVE-2026-82612 HIGH 7.3 A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item … Aug 31, 2026