Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82636 | HIGH | 7.9 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is … | Aug 30, 2026 |
| CVE-2026-82544 | MEDIUM | 4.3 | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password … | Aug 30, 2026 |
| CVE-2026-82635 | HIGH | 8.8 | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal … | Aug 30, 2026 |
| CVE-2026-82634 | MEDIUM | 6.5 | Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template … | Aug 30, 2026 |
| CVE-2026-82633 | MEDIUM | 4.3 | Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of … | Aug 30, 2026 |
| CVE-2026-82543 | HIGH | 7.3 | A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit … | Aug 30, 2026 |
| CVE-2026-82542 | CRITICAL | 10.0 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa … | Aug 30, 2026 |
| CVE-2026-82541 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. … | Aug 30, 2026 |
| CVE-2026-82540 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument … | Aug 30, 2026 |
| CVE-2026-81318 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an … | Aug 30, 2026 |
| CVE-2026-81316 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing … | Aug 30, 2026 |
| CVE-2026-80227 | UNKNOWN | — | Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed … | Aug 30, 2026 |
| CVE-2026-78691 | UNKNOWN | — | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or … | Aug 30, 2026 |
| CVE-2026-78228 | UNKNOWN | — | Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker … | Aug 30, 2026 |
| CVE-2026-78038 | UNKNOWN | — | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an … | Aug 30, 2026 |
| CVE-2026-77454 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both … | Aug 30, 2026 |
| CVE-2026-82539 | CRITICAL | 9.1 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation … | Aug 30, 2026 |
| CVE-2026-82488 | LOW | 3.5 | A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads … | Aug 30, 2026 |
| CVE-2026-82487 | MEDIUM | 6.3 | A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can … | Aug 30, 2026 |
| CVE-2026-82486 | MEDIUM | 5.0 | A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation … | Aug 30, 2026 |
| CVE-2026-82485 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such … | Aug 30, 2026 |
| CVE-2026-82484 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the … | Aug 30, 2026 |
| CVE-2026-82483 | LOW | 3.5 | A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden … | Aug 30, 2026 |
| CVE-2026-82482 | LOW | 3.5 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the … | Aug 30, 2026 |
| CVE-2026-81766 | UNKNOWN | — | The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 … | Aug 30, 2026 |