Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78693 | UNKNOWN | — | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its … | Aug 30, 2026 |
| CVE-2026-56715 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 30, 2026 |
| CVE-2026-56713 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 30, 2026 |
| CVE-2026-82556 | MEDIUM | 6.3 | A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. … | Aug 30, 2026 |
| CVE-2026-82555 | LOW | 3.7 | A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such … | Aug 30, 2026 |
| CVE-2026-82554 | MEDIUM | 4.3 | A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument … | Aug 30, 2026 |
| CVE-2026-81322 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone … | Aug 30, 2026 |
| CVE-2026-81319 | UNKNOWN | — | Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, … | Aug 30, 2026 |
| CVE-2026-82553 | MEDIUM | 6.3 | A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of … | Aug 30, 2026 |
| CVE-2026-82552 | MEDIUM | 4.3 | A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the … | Aug 30, 2026 |
| CVE-2026-82551 | MEDIUM | 5.3 | A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing … | Aug 30, 2026 |
| CVE-2026-82550 | MEDIUM | 5.3 | A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of … | Aug 30, 2026 |
| CVE-2026-82549 | HIGH | 8.3 | A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation … | Aug 30, 2026 |
| CVE-2026-78699 | UNKNOWN | — | Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's … | Aug 30, 2026 |
| CVE-2026-82658 | MEDIUM | 4.3 | Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers … | Aug 30, 2026 |
| CVE-2026-82657 | HIGH | 7.5 | Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and … | Aug 30, 2026 |
| CVE-2026-82656 | LOW | 2.6 | Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments … | Aug 30, 2026 |
| CVE-2026-82655 | HIGH | 7.5 | Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers … | Aug 30, 2026 |
| CVE-2026-82654 | HIGH | 8.9 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's … | Aug 30, 2026 |
| CVE-2026-82653 | HIGH | 8.9 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers … | Aug 30, 2026 |
| CVE-2026-82652 | MEDIUM | 5.3 | SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible … | Aug 30, 2026 |
| CVE-2026-82651 | MEDIUM | 4.9 | SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication … | Aug 30, 2026 |
| CVE-2026-82650 | MEDIUM | 4.4 | SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint … | Aug 30, 2026 |
| CVE-2026-82649 | UNKNOWN | — | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables … | Aug 30, 2026 |
| CVE-2026-82648 | HIGH | 7.1 | WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers … | Aug 30, 2026 |