CVE IDSeverityCVSSDescriptionDate
CVE-2026-82417MEDIUM5.3### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` proper…2026-08-30
CVE-2026-75847NAN/ACleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit…2026-08-30
CVE-2026-77831NAN/AInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a…2026-08-30
CVE-2026-77970NAN/ACleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit…2026-08-30
CVE-2026-82562LOW3.7### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separate…2026-08-30
CVE-2026-75759NAN/AImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attack…2026-08-30
CVE-2026-77846NAN/AImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows…2026-08-30
CVE-2026-15980CRITICAL9.8The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi…2026-08-30
CVE-2026-82478HIGH7.3A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread:…2026-08-30
CVE-2026-82479MEDIUM6.3A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/p…2026-08-30
CVE-2026-82480HIGH7.4A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUs…2026-08-30
CVE-2026-14307HIGH7.1The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before refle…2026-08-30
CVE-2026-14835MEDIUM6.8The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape…2026-08-30
CVE-2026-19722NAN/AThe WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of…2026-08-30
CVE-2026-76585HIGH8.8The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content …2026-08-30
CVE-2026-78364LOW3.5The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before out…2026-08-30
CVE-2026-81660HIGH8.8The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate o…2026-08-30
CVE-2026-81766MEDIUM6.6The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install R…2026-08-30
CVE-2026-82482LOW3.5A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This a…2026-08-30
CVE-2026-82483LOW3.5A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unkn…2026-08-30
CVE-2026-82484MEDIUM6.3A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the f…2026-08-30
CVE-2026-82485MEDIUM6.3A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability …2026-08-30
CVE-2026-82486MEDIUM5.0A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of t…2026-08-30
CVE-2026-82487MEDIUM6.3A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipul…2026-08-30
CVE-2026-82488LOW3.5A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the co…2026-08-30
CVE-2026-82539CRITICAL9.1A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilter…2026-08-30
CVE-2026-77454NAN/AIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorizat…2026-08-30
CVE-2026-78038NAN/AImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project as…2026-08-30
CVE-2026-78228NAN/AUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error …2026-08-30
CVE-2026-78691NAN/AImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a …2026-08-30
CVE-2026-80227NAN/AIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newlin…2026-08-30
CVE-2026-81316NAN/AIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value com…2026-08-30
CVE-2026-81318NAN/AIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant app…2026-08-30
CVE-2026-82540MEDIUM6.3A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function…2026-08-30
CVE-2026-82541MEDIUM6.3A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerabi…2026-08-30
CVE-2026-82542CRITICAL10.0A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing…2026-08-30
CVE-2026-82543HIGH7.3A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_f…2026-08-30
CVE-2026-82633MEDIUM4.3Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups…2026-08-30
CVE-2026-82634MEDIUM6.5Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that a…2026-08-30
CVE-2026-82635HIGH8.8Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's …2026-08-30
CVE-2026-82544MEDIUM4.3A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_pass…2026-08-30
CVE-2026-82636HIGH7.9Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom…2026-08-30
CVE-2026-82637MEDIUM5.3browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, all…2026-08-30
CVE-2026-82638HIGH7.5jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated a…2026-08-30
CVE-2026-82639HIGH7.5NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy end…2026-08-30
CVE-2026-82640MEDIUM5.5browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without enc…2026-08-30
CVE-2026-82641HIGH8.6keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authen…2026-08-30
CVE-2026-82642HIGH8.8Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is san…2026-08-30
CVE-2026-82545MEDIUM6.3A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function…2026-08-30
CVE-2026-82547MEDIUM6.5A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the …2026-08-30
22 / 7715