Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82611 | HIGH | 7.3 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of … | Aug 31, 2026 |
| CVE-2026-82610 | HIGH | 7.3 | A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of the file /rider/login.php of the component … | Aug 31, 2026 |
| CVE-2026-82609 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit.php. The manipulation of the argument … | Aug 31, 2026 |
| CVE-2026-82722 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table … | Aug 31, 2026 |
| CVE-2026-82681 | UNKNOWN | — | Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's … | Aug 31, 2026 |
| CVE-2026-82673 | UNKNOWN | — | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. … | Aug 31, 2026 |
| CVE-2026-82608 | HIGH | 7.4 | A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a … | Aug 31, 2026 |
| CVE-2026-82607 | HIGH | 7.3 | A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php … | Aug 31, 2026 |
| CVE-2026-82605 | MEDIUM | 4.3 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such … | Aug 31, 2026 |
| CVE-2026-81853 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key form … | Aug 31, 2026 |
| CVE-2026-81852 | UNKNOWN | — | Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 … | Aug 31, 2026 |
| CVE-2026-77850 | UNKNOWN | — | Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField highlight … | Aug 31, 2026 |
| CVE-2026-75757 | UNKNOWN | — | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to … | Aug 31, 2026 |
| CVE-2026-82604 | MEDIUM | 4.3 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes … | Aug 31, 2026 |
| CVE-2026-82603 | MEDIUM | 5.4 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The … | Aug 31, 2026 |
| CVE-2026-82602 | MEDIUM | 5.3 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization … | Aug 31, 2026 |
| CVE-2026-82601 | MEDIUM | 4.3 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument … | Aug 31, 2026 |
| CVE-2026-82600 | HIGH | 7.3 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a … | Aug 31, 2026 |
| CVE-2026-82580 | UNKNOWN | — | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised … | Aug 31, 2026 |
| CVE-2026-82579 | UNKNOWN | — | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop … | Aug 31, 2026 |
| CVE-2026-82564 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including … | Aug 31, 2026 |
| CVE-2026-75760 | UNKNOWN | — | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when … | Aug 31, 2026 |
| CVE-2026-82599 | MEDIUM | 5.4 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar … | Aug 31, 2026 |
| CVE-2026-82598 | HIGH | 7.3 | A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation … | Aug 31, 2026 |
| CVE-2026-82597 | HIGH | 7.4 | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to … | Aug 31, 2026 |