Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-82541 — itsourcecode Sales and Inventory System sup_edit.php sql injection

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the…

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82540 — itsourcecode Sales and Inventory System cust_searchfrm.php sql injection

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql …

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-81318 — Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggreg…

ash_sql | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-81316 — Same-named aggregates with differing filters are conflated in AshSql

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, …

ash_sql | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-80227 — SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql

Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality che…

ash_sql | Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-78691 — Unescaped backslash allows LIKE wildcard injection in AshSql string search

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/…

ash_sql | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-78228 — Unbounded handle_error recursion enables denial of service in AshOban triggers

Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. T…

ash_oban | Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-78038 — Job argument injection via :args overrides primary_key and tenant in AshOban

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to r…

ash_oban | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-77454 — exists/2 predicate silently dropped on limited relationships with a parent() filter in As…

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_…

ash_sql | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
9.1 CRITICAL
CVE-2026-82539 — TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of…

a720r_firmware a720r | Remote | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.0 MEDIUM
CVE-2026-82488 — Beetel 450TC3 User Management cross site scripting

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site sc…

450tc3 | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82487 — Beetel 450TC3 password recovery

A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploi…

450tc3 | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.1 MEDIUM
CVE-2026-82486 — SiteServer SSCMS Agent Installation Workflow access control

A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument Secur…

sscms | Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82485 — itsourcecode Sales and Inventory System pro_edit.php sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the arg…

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82484 — itsourcecode Sales and Inventory System emp_searchfrm.php sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. …

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.0 MEDIUM
CVE-2026-82483 — coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cro…

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The …

coppermine_photo_gallery | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.0 MEDIUM
CVE-2026-82482 — coppermine-gallery Coppermine Photo Gallery edit_profile Endpoint profile.php cross site …

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint…

coppermine_photo_gallery | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-81766 — Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation v…

The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-su…

| Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-81660 — Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and output…

| Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-78364 — MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low …

| Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11969 Results