Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82647 | MEDIUM | 6.1 | WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin … | Aug 30, 2026 |
| CVE-2026-82646 | MEDIUM | 6.1 | WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML … | Aug 30, 2026 |
| CVE-2026-82645 | HIGH | 8.6 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and … | Aug 30, 2026 |
| CVE-2026-82644 | HIGH | 7.5 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its … | Aug 30, 2026 |
| CVE-2026-82643 | MEDIUM | 6.5 | WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to … | Aug 30, 2026 |
| CVE-2026-82548 | MEDIUM | 5.3 | A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information … | Aug 30, 2026 |
| CVE-2026-82547 | MEDIUM | 6.5 | A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete … | Aug 30, 2026 |
| CVE-2026-82545 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the … | Aug 30, 2026 |
| CVE-2026-82642 | HIGH | 8.8 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that … | Aug 30, 2026 |
| CVE-2026-82641 | HIGH | 8.6 | keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic … | Aug 30, 2026 |
| CVE-2026-82640 | MEDIUM | 5.5 | browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to … | Aug 30, 2026 |
| CVE-2026-82639 | HIGH | 7.5 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API … | Aug 30, 2026 |
| CVE-2026-82638 | HIGH | 7.5 | jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping … | Aug 30, 2026 |
| CVE-2026-82637 | MEDIUM | 5.3 | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute … | Aug 30, 2026 |
| CVE-2026-82636 | HIGH | 7.9 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is … | Aug 30, 2026 |
| CVE-2026-82544 | MEDIUM | 4.3 | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password … | Aug 30, 2026 |
| CVE-2026-82635 | HIGH | 8.8 | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal … | Aug 30, 2026 |
| CVE-2026-82634 | MEDIUM | 6.5 | Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template … | Aug 30, 2026 |
| CVE-2026-82633 | MEDIUM | 4.3 | Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of … | Aug 30, 2026 |
| CVE-2026-82543 | HIGH | 7.3 | A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit … | Aug 30, 2026 |
| CVE-2026-82542 | CRITICAL | 10.0 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa … | Aug 30, 2026 |
| CVE-2026-82541 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. … | Aug 30, 2026 |
| CVE-2026-82540 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument … | Aug 30, 2026 |
| CVE-2026-81318 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an … | Aug 30, 2026 |
| CVE-2026-81316 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing … | Aug 30, 2026 |