| CVE-2026-82417 | MEDIUM | 5.3 | ### Summary
`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` proper… | 2026-08-30 |
| CVE-2026-75847 | NA | N/A | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit… | 2026-08-30 |
| CVE-2026-77831 | NA | N/A | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a… | 2026-08-30 |
| CVE-2026-77970 | NA | N/A | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit… | 2026-08-30 |
| CVE-2026-82562 | LOW | 3.7 | ### Summary
When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separate… | 2026-08-30 |
| CVE-2026-75759 | NA | N/A | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attack… | 2026-08-30 |
| CVE-2026-77846 | NA | N/A | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows… | 2026-08-30 |
| CVE-2026-15980 | CRITICAL | 9.8 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi… | 2026-08-30 |
| CVE-2026-82478 | HIGH | 7.3 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread:… | 2026-08-30 |
| CVE-2026-82479 | MEDIUM | 6.3 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/p… | 2026-08-30 |
| CVE-2026-82480 | HIGH | 7.4 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUs… | 2026-08-30 |
| CVE-2026-14307 | HIGH | 7.1 | The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before refle… | 2026-08-30 |
| CVE-2026-14835 | MEDIUM | 6.8 | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape… | 2026-08-30 |
| CVE-2026-19722 | NA | N/A | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of… | 2026-08-30 |
| CVE-2026-76585 | HIGH | 8.8 | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content … | 2026-08-30 |
| CVE-2026-78364 | LOW | 3.5 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before out… | 2026-08-30 |
| CVE-2026-81660 | HIGH | 8.8 | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate o… | 2026-08-30 |
| CVE-2026-81766 | MEDIUM | 6.6 | The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install R… | 2026-08-30 |
| CVE-2026-82482 | LOW | 3.5 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This a… | 2026-08-30 |
| CVE-2026-82483 | LOW | 3.5 | A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unkn… | 2026-08-30 |
| CVE-2026-82484 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the f… | 2026-08-30 |
| CVE-2026-82485 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability … | 2026-08-30 |
| CVE-2026-82486 | MEDIUM | 5.0 | A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of t… | 2026-08-30 |
| CVE-2026-82487 | MEDIUM | 6.3 | A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipul… | 2026-08-30 |
| CVE-2026-82488 | LOW | 3.5 | A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the co… | 2026-08-30 |
| CVE-2026-82539 | CRITICAL | 9.1 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilter… | 2026-08-30 |
| CVE-2026-77454 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorizat… | 2026-08-30 |
| CVE-2026-78038 | NA | N/A | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project as… | 2026-08-30 |
| CVE-2026-78228 | NA | N/A | Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error … | 2026-08-30 |
| CVE-2026-78691 | NA | N/A | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a … | 2026-08-30 |
| CVE-2026-80227 | NA | N/A | Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newlin… | 2026-08-30 |
| CVE-2026-81316 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value com… | 2026-08-30 |
| CVE-2026-81318 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant app… | 2026-08-30 |
| CVE-2026-82540 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function… | 2026-08-30 |
| CVE-2026-82541 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerabi… | 2026-08-30 |
| CVE-2026-82542 | CRITICAL | 10.0 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing… | 2026-08-30 |
| CVE-2026-82543 | HIGH | 7.3 | A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_f… | 2026-08-30 |
| CVE-2026-82633 | MEDIUM | 4.3 | Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups… | 2026-08-30 |
| CVE-2026-82634 | MEDIUM | 6.5 | Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that a… | 2026-08-30 |
| CVE-2026-82635 | HIGH | 8.8 | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's … | 2026-08-30 |
| CVE-2026-82544 | MEDIUM | 4.3 | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_pass… | 2026-08-30 |
| CVE-2026-82636 | HIGH | 7.9 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom… | 2026-08-30 |
| CVE-2026-82637 | MEDIUM | 5.3 | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, all… | 2026-08-30 |
| CVE-2026-82638 | HIGH | 7.5 | jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated a… | 2026-08-30 |
| CVE-2026-82639 | HIGH | 7.5 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy end… | 2026-08-30 |
| CVE-2026-82640 | MEDIUM | 5.5 | browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without enc… | 2026-08-30 |
| CVE-2026-82641 | HIGH | 8.6 | keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authen… | 2026-08-30 |
| CVE-2026-82642 | HIGH | 8.8 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is san… | 2026-08-30 |
| CVE-2026-82545 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function… | 2026-08-30 |
| CVE-2026-82547 | MEDIUM | 6.5 | A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the … | 2026-08-30 |