Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82658 | MEDIUM | 4.3 | Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers … | Aug 30, 2026 |
| CVE-2026-82657 | HIGH | 7.5 | Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and … | Aug 30, 2026 |
| CVE-2026-82656 | LOW | 2.6 | Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments … | Aug 30, 2026 |
| CVE-2026-82655 | HIGH | 7.5 | Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers … | Aug 30, 2026 |
| CVE-2026-82654 | HIGH | 8.9 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's … | Aug 30, 2026 |
| CVE-2026-82653 | HIGH | 8.9 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers … | Aug 30, 2026 |
| CVE-2026-82652 | MEDIUM | 5.3 | SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible … | Aug 30, 2026 |
| CVE-2026-82651 | MEDIUM | 4.9 | SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication … | Aug 30, 2026 |
| CVE-2026-82650 | MEDIUM | 4.4 | SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint … | Aug 30, 2026 |
| CVE-2026-82649 | UNKNOWN | — | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables … | Aug 30, 2026 |
| CVE-2026-82648 | HIGH | 7.1 | WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers … | Aug 30, 2026 |
| CVE-2026-82647 | MEDIUM | 6.1 | WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin … | Aug 30, 2026 |
| CVE-2026-82646 | MEDIUM | 6.1 | WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML … | Aug 30, 2026 |
| CVE-2026-82645 | HIGH | 8.6 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and … | Aug 30, 2026 |
| CVE-2026-82644 | HIGH | 7.5 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its … | Aug 30, 2026 |
| CVE-2026-82643 | MEDIUM | 6.5 | WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to … | Aug 30, 2026 |
| CVE-2026-82548 | MEDIUM | 5.3 | A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information … | Aug 30, 2026 |
| CVE-2026-82547 | MEDIUM | 6.5 | A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete … | Aug 30, 2026 |
| CVE-2026-82545 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the … | Aug 30, 2026 |
| CVE-2026-82642 | HIGH | 8.8 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that … | Aug 30, 2026 |
| CVE-2026-82641 | HIGH | 8.6 | keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic … | Aug 30, 2026 |
| CVE-2026-82640 | MEDIUM | 5.5 | browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to … | Aug 30, 2026 |
| CVE-2026-82639 | HIGH | 7.5 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API … | Aug 30, 2026 |
| CVE-2026-82638 | HIGH | 7.5 | jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping … | Aug 30, 2026 |
| CVE-2026-82637 | MEDIUM | 5.3 | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute … | Aug 30, 2026 |