Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-82607 — Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simp…

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the comp…

| Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
2.1 LOW
CVE-2026-81852 — AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass

Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without…

Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
2.0 LOW
CVE-2026-82681 — Query-parameter injection in AshAdmin row-action links via unencoded string primary keys

Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Tabl…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.4 HIGH
CVE-2026-77850 — Stored XSS in AshAdmin relationship typeahead via unescaped label_field content

Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.C…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.3 HIGH
CVE-2026-82722 — AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node …

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node. T…

Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.3 HIGH
CVE-2026-75757 — AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from …

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, …

Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2026-82604 — BareBones BBEdit Java Language recursion

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of …

bbedit | Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.5 MEDIUM
CVE-2026-82603 — SeaCMS Comment Cache member.php del_pl path traversal

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument it…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.5 MEDIUM
CVE-2026-82602 — SeaCMS ass.php authorization

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initia…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.0 MEDIUM
CVE-2026-82601 — SeaCMS err.php cross site scripting

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack ca…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82600 — SeaCMS zyapi.php sql injection

A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids resul…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2026-82580 — AshAi echoes raw tool exception messages into the conversation, disclosing internal detai…

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised w…

Remote | Information Disclosure
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.0 MEDIUM
CVE-2026-82579 — AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of…

Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated mode…

Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82564 — Identity tool filter in AshAi accepts operator maps, allowing update or destroy of uniden…

Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every r…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-75760 — AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a u…

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.…

Remote | Information Disclosure
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-82605 — BareBones BBEdit Lasso Language Tokenizer infinite loop

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The a…

bbedit | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.5 MEDIUM
CVE-2026-82599 — SeaCMS Avatar Upload member.php unlink path traversal

A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulatio…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82598 — SeaCMS Template search.php parseIf code injection

A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.4 HIGH
CVE-2026-82597 — TOTOLINK NR1800X cstecgi.cgi setUssd command injection

A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command in…

nr1800x | Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.4 HIGH
CVE-2026-81315 — MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header

Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server …

Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 11956 Results