Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.9 MEDIUM
CVE-2026-82651 — SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes requi…

siyuan | Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.4 MEDIUM
CVE-2026-82650 — SiYuan before v3.8.1 Path Traversal via /api/template/render

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/…

siyuan | Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.0 HIGH
CVE-2026-82649 — SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path

SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as …

siyuan | Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.1 HIGH
CVE-2026-82648 — WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass …

avideo | Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.1 MEDIUM
CVE-2026-82647 — WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php

WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks …

avideo | Remote | Cross-Site Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.1 MEDIUM
CVE-2026-82646 — WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php

WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML m…

avideo | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.6 HIGH
CVE-2026-82645 — AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both th…

avideo | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82644 — WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt co…

avideo | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82643 — WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit corr…

avideo | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82548 — Linux Foundation Magma InitialUEMessage information disclosure

A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure.…

magma magma | Remote | Information Disclosure
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82547 — Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The ma…

magma magma | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82545 — itsourcecode Sales and Inventory System sup_searchfrm.php sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql i…

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.8 HIGH
CVE-2026-82642 — Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary …

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TA…

Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.6 HIGH
CVE-2026-82641 — keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can…

Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.5 MEDIUM
CVE-2026-82640 — browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings dire…

browser_use | Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82639 — NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header …

nextchat | Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82638 — jina-ai reader Server-Side Request Forgery via disabled private-address guard

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable…

reader | Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-82637 — browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths …

browser_use | Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.9 HIGH
CVE-2026-82636 — Qubes OS OS Command Injection Vulnerability

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to proces…

| Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-82544 — wger-project wger Password Reset gym.py reset_user_password cross-site request forgery

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manip…

wger | Remote | Cross-Site Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11940 Results