Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-78693 — Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal …

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_hand…

ash_graphql | Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82556 — Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forge…

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration H…

forgejo | Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
3.7 LOW
CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Ha…

n600r_firmware n600r | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.0 MEDIUM
CVE-2026-82554 — SourceCodester Queue Management System add_customer.php cross site scripting

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting…

queue_management_system | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-81322 — Cloaked plaintext leaks through a non-sensitive action argument in AshCloak

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a vali…

ash_cloak | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-81319 — Unsafe deserialization of decrypted terms enables node DoS in AshCloak

Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom cre…

ash_cloak | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82553 — sambitraj Student Management System Student Dashboard student_dashboard.php mysqli_query …

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.p…

student_management_system | Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.3 MEDIUM
CVE-2026-82552 — Linux Foundation Magma gNB Termination ngap_amf.c denial of service

A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Terminati…

magma magma | Remote | Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82551 — Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to …

magma magma | Remote | Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82550 — Linux Foundation Magma NGSetupRequest input validation

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-Default…

magma magma | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.3 HIGH
CVE-2026-82549 — Linux Foundation Magma SecurityModeComplete integrity check

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integ…

magma magma | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.2 HIGH
CVE-2026-78699 — rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres

Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repoi…

ash_postgres | Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.3 MEDIUM
CVE-2026-82658 — Admidio before 5.0.12 Broken Access Control via profile_function.php

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Atta…

admidio | Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82657 — Admidio before 5.0.12 Authentication Bypass via RSS feeds

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements …

admidio | Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.6 LOW
CVE-2026-82656 — Admidio before 5.0.12 Path Traversal via Photo ZIP Download

Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entr…

admidio | Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82655 — Admidio before 5.0.12 SQL Injection via relation_type_list

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attack…

admidio | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.9 HIGH
CVE-2026-82654 — SiYuan before v3.8.1 Stored XSS via block name

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags th…

siyuan | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.9 HIGH
CVE-2026-82653 — SiYuan before v3.8.1 Stored XSS via confirmDialog

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Att…

siyuan | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-82652 — SiYuan before v3.8.1 Information Disclosure via Publish Access

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content…

siyuan | Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.9 MEDIUM
CVE-2026-82651 — SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes requi…

siyuan | Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11959 Results