Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-82587 — Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This ma…

Remote | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.3 LOW
CVE-2026-82367 — Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber…

Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.…

Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.3 LOW
CVE-2026-81643 — Broken access control in AshGraphql subscription batcher applies authorization suppressio…

Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send…

Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.7 HIGH
CVE-2026-81636 — Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables d…

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unb…

Remote | Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.9 MEDIUM
CVE-2026-81633 — Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown typ…

Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resol…

Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.1 HIGH
CVE-2026-80223 — Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory wit…

Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription res…

Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.9 MEDIUM
CVE-2026-78693 — Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal …

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_hand…

Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82556 — Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forge…

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration H…

Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
3.7 LOW
CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Ha…

n600r | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.0 MEDIUM
CVE-2026-82554 — SourceCodester Queue Management System add_customer.php cross site scripting

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting…

Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-81322 — Cloaked plaintext leaks through a non-sensitive action argument in AshCloak

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a vali…

| Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-81319 — Unsafe deserialization of decrypted terms enables node DoS in AshCloak

Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom cre…

| Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82553 — sambitraj Student Management System Student Dashboard student_dashboard.php mysqli_query …

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.p…

Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.3 MEDIUM
CVE-2026-82552 — Linux Foundation Magma gNB Termination ngap_amf.c denial of service

A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Terminati…

magma | Remote | Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82551 — Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to …

magma magma | Remote | Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82550 — Linux Foundation Magma NGSetupRequest input validation

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-Default…

magma magma | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.3 HIGH
CVE-2026-82549 — Linux Foundation Magma SecurityModeComplete integrity check

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integ…

magma magma | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.2 HIGH
CVE-2026-78699 — rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres

Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repoi…

ash_postgres | Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.3 MEDIUM
CVE-2026-82658 — Admidio before 5.0.12 Broken Access Control via profile_function.php

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Atta…

Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82657 — Admidio before 5.0.12 Authentication Bypass via RSS feeds

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements …

Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11960 Results