Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-82657 — Admidio before 5.0.12 Authentication Bypass via RSS feeds

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements …

Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.6 LOW
CVE-2026-82656 — Admidio before 5.0.12 Path Traversal via Photo ZIP Download

Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entr…

Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82655 — Admidio before 5.0.12 SQL Injection via relation_type_list

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attack…

Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.9 HIGH
CVE-2026-82654 — SiYuan before v3.8.1 Stored XSS via block name

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags th…

Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.9 HIGH
CVE-2026-82653 — SiYuan before v3.8.1 Stored XSS via confirmDialog

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Att…

Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-82652 — SiYuan before v3.8.1 Information Disclosure via Publish Access

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content…

Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.9 MEDIUM
CVE-2026-82651 — SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes requi…

Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.4 MEDIUM
CVE-2026-82650 — SiYuan before v3.8.1 Path Traversal via /api/template/render

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/…

Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.0 HIGH
CVE-2026-82649 — SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path

SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as …

| Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.1 HIGH
CVE-2026-82648 — WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass …

avideo | Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.1 MEDIUM
CVE-2026-82647 — WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php

WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks …

avideo | Remote | Cross-Site Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.1 MEDIUM
CVE-2026-82646 — WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php

WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML m…

avideo | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.6 HIGH
CVE-2026-82645 — AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both th…

avideo | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82644 — WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt co…

avideo | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82643 — WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit corr…

avideo | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82548 — Linux Foundation Magma InitialUEMessage information disclosure

A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure.…

magma | Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82547 — Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The ma…

magma | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82545 — itsourcecode Sales and Inventory System sup_searchfrm.php sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql i…

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.8 HIGH
CVE-2026-82642 — Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary …

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TA…

Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.6 HIGH
CVE-2026-82641 — keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can…

Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11951 Results