CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82611
7.3 HIGH

A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of …

Aug 31, 2026
CVE-2026-82610
7.3 HIGH

A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of the file /rider/login.php of the component …

Aug 31, 2026
CVE-2026-82609
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit.php. The manipulation of the argument …

Aug 31, 2026
CVE-2026-82722

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table …

Aug 31, 2026
CVE-2026-82681

Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's …

Aug 31, 2026
CVE-2026-82673

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. …

Aug 31, 2026
CVE-2026-82608
7.4 HIGH

A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a …

Aug 31, 2026
CVE-2026-82607
7.3 HIGH

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php …

Aug 31, 2026
CVE-2026-82605
4.3 MEDIUM

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such …

Aug 31, 2026
CVE-2026-81853

Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key form …

Aug 31, 2026
CVE-2026-81852

Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 …

Aug 31, 2026
CVE-2026-77850

Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField highlight …

Aug 31, 2026
CVE-2026-75757

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to …

Aug 31, 2026
CVE-2026-82604
4.3 MEDIUM

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes …

Aug 31, 2026
CVE-2026-82603
5.4 MEDIUM

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The …

Aug 31, 2026
CVE-2026-82602
5.3 MEDIUM

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization …

Aug 31, 2026
CVE-2026-82601
4.3 MEDIUM

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument …

Aug 31, 2026
CVE-2026-82600
7.3 HIGH

A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a …

Aug 31, 2026
CVE-2026-82580

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised …

Aug 31, 2026
CVE-2026-82579

Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop …

Aug 31, 2026
CVE-2026-82564

Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including …

Aug 31, 2026
CVE-2026-75760

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when …

Aug 31, 2026
CVE-2026-82599
5.4 MEDIUM

A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar …

Aug 31, 2026
CVE-2026-82598
7.3 HIGH

A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation …

Aug 31, 2026
CVE-2026-82597
7.4 HIGH

A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to …

Aug 31, 2026
CVE-2026-81315

Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a …

Aug 31, 2026
CVE-2026-77956

Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt …

Aug 31, 2026
CVE-2026-82596
3.3 LOW

A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. …

Aug 31, 2026
CVE-2026-82595
7.4 HIGH

A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command …

Aug 31, 2026
CVE-2026-82594
5.0 MEDIUM

A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to …

Aug 31, 2026
CVE-2026-82593
9.9 CRITICAL

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. …

Aug 31, 2026
CVE-2026-82592
9.9 CRITICAL

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The …

Aug 30, 2026
CVE-2026-82591
5.3 MEDIUM

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file …

Aug 30, 2026
CVE-2026-82590
4.3 MEDIUM

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. …

Aug 30, 2026
CVE-2026-82589
4.3 MEDIUM

A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message …

Aug 30, 2026
CVE-2026-82588
4.3 MEDIUM

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such …

Aug 30, 2026
CVE-2026-56718
7.5 HIGH

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read …

Aug 30, 2026
CVE-2026-64844

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-64843

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-64842

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-64841

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-64840

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-64839

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-56716

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2026
CVE-2026-82587
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This manipulation …

Aug 30, 2026
CVE-2026-82367

Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the …

Aug 30, 2026
CVE-2026-81643

Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first …

Aug 30, 2026
CVE-2026-81636

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an …

Aug 30, 2026
CVE-2026-81633

Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the …

Aug 30, 2026
CVE-2026-80223

Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in …

Aug 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.