Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-82638 — jina-ai reader Server-Side Request Forgery via disabled private-address guard

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable…

reader | Remote | Server-Side Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-82637 — browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths …

Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.9 HIGH
CVE-2026-82636 — Qubes OS OS Command Injection Vulnerability

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to proces…

| Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-82544 — wger-project wger Password Reset gym.py reset_user_password cross-site request forgery

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manip…

Remote | Cross-Site Request Forgery
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
8.8 HIGH
CVE-2026-82635 — Pake arbitrary file write via unsanitized download_file filename

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences …

Remote | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82634 — Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview En…

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template …

Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.3 MEDIUM
CVE-2026-82633 — Dolibarr 10.0.0 before 24.0.0 Missing Authorization on REST Users Groups Endpoint

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other u…

Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82543 — vastsa FileCodeBox Pickup Limit views.py update_file_usage race condition

A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit Handler. Performin…

Remote | Race Condition
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
10.0 CRITICAL
CVE-2026-82542 — Tenda HG10 Boa Web Server formIPv6Routing buffer overflow

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipul…

hg10 | Remote | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82541 — itsourcecode Sales and Inventory System sup_edit.php sql injection

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the…

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82540 — itsourcecode Sales and Inventory System cust_searchfrm.php sql injection

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql …

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-81318 — Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggreg…

| Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-81316 — Same-named aggregates with differing filters are conflated in AshSql

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, …

| Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-80227 — SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql

Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality che…

| Misconfiguration
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-78691 — Unescaped backslash allows LIKE wildcard injection in AshSql string search

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/…

| Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-78228 — Unbounded handle_error recursion enables denial of service in AshOban triggers

Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. T…

| Denial of Service
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-78038 — Job argument injection via :args overrides primary_key and tenant in AshOban

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to r…

| Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.9 MEDIUM
CVE-2026-77454 — exists/2 predicate silently dropped on limited relationships with a parent() filter in As…

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_…

| Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
9.1 CRITICAL
CVE-2026-82539 — TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of…

a720r | Remote | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.0 MEDIUM
CVE-2026-82488 — Beetel 450TC3 User Management cross site scripting

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site sc…

Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11970 Results