Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 30 August 2026

RSS

318 vulnerabilities published on 30 August 2026

Severity:
Tenda HG10 router can be crashed by remote traffic
CVE-2026-82542
The Tenda HG10 router’s web administration page has a coding mistake that lets an attacker send specially crafted data and overflow a memory area. This can be done from outside the network and may cau...
9.3
D-Link DIR-825M router allows remote code execution via disk format
CVE-2026-82592
The router’s disk formatting feature can be tricked into overwriting memory, letting an attacker run their own code from anywhere on the internet. This could let a hacker take control of the device or...
8.6
MyHome Core plugin lets attackers take over user accounts
CVE-2026-15980
The MyHome Core add‑on for WordPress lets anyone create a special link that logs in as any user, even an administrator, if the site uses the older WPBakery setup with front‑end registration turned on....
9.8
TOTOLINK A720R router can be remotely crashed via MAC filter
CVE-2026-82539
The A720R router’s MAC‑filtering feature can be tricked by sending a specially crafted request, causing the device’s memory to become corrupted. This can make the router stop working or become unstabl...
8.5
Red Hat Hardened Images packages need security update
RHSA-2026:60866
The Red Hat Hardened Images software includes several components that have known security weaknesses. If left unpatched, these weaknesses could let attackers gain unauthorized access or disrupt operat...
9.1
erlef OIDC library may accept fake encrypted login tokens
CVE-2026-75759 EEF-CVE-2026-75759 GHSA-533g-4vf3-xwrj
The erlef OIDC software that handles single‑sign‑on can treat an encrypted login token that lacks a proper signature (proof it really came from the trusted source) as valid. This allows an attacker to...
9.1
SiYuan lets malicious scripts run from block names
CVE-2026-82654
Older versions of SiYuan do not clean the text used for block names, aliases, and notes when showing hints, backlinks, or navigation paths. An attacker could insert HTML or script code into a block na...
9.3
SiYuan before 3.8.1 runs code from malicious package names
CVE-2026-82653 GHSA-hvwp-43j9-4xgf
Versions of SiYuan prior to 3.8.1 can be tricked into executing hidden scripts when a user removes a package or opens an encrypted notebook. An attacker could publish a package with a specially crafte...
9.3
Readest e‑book app could run any code via hidden iframe
CVE-2026-82642
Older versions of the Readest e‑book reader did not fully filter content inside an iframe's srcdoc attribute. This lets a malicious e‑book embed hidden code that can run and control the application. U...
8.8
Pake lets attackers overwrite files via download command
CVE-2026-82635
The Pake tool (versions before 3.13.1) lets a program tell the system to save a file using any name the attacker chooses. By using special path tricks, the attacker can place the file outside the norm...
8.8
Groundhogg plugin lets attackers inject code via form
CVE-2026-81660
The Groundhogg CRM and marketing plugin for WordPress, versions before 4.5.13, does not properly clean data entered in certain form fields. This allows anyone on the internet to add hidden code that w...
8.8
WooCommerce Customer Reviews plugin can let attackers inject code
CVE-2026-76585
The Customer Reviews add‑on for WooCommerce (versions before 5.118.0) does not properly clean the text that users submit in reviews. This means a stranger could place hidden scripts in a review that r...
8.8
AshGraphQL pagination can overload servers
CVE-2026-81636 EEF-CVE-2026-81636 GHSA-mwc4-r9fc-h6mg
When a client asks for a very large page of data using the "first" or "last" options, the system fails to limit how much it reads from the database. This can cause the server to become slow or stop re...
8.7
AVideo reveals live stream passwords without login
CVE-2026-82645
The AVideo video platform can return the passwords and URLs used to broadcast to services like YouTube, Facebook, and Twitch even to people who are not logged in. An attacker can create a fake token a...
9.2
Keploy 3.1.0‑3.6.25 lets anyone grab TLS keys
CVE-2026-82641
Versions 3.1.0 through 3.6.25 of Keploy run a control‑plane web server that anyone on the network can reach. Through this server an attacker could download the TLS session keys used to encrypt traffic...
8.8
Red Hat Hardened Images packages need security update
RHSA-2026:60853
The Red Hat Hardened Images software includes several components that have known security weaknesses. If left unpatched, these weaknesses could let attackers gain unauthorized access or disrupt operat...
8.4
Magma 1.9.0 may accept false integrity check
CVE-2026-82549
The Magma software version 1.9.0 has a mistake in a routine that confirms data integrity. An attacker on the network could trick the system into believing altered data is authentic. Update to a newer ...
5.5
Qubes OS runs commands when copying to a malicious VM
CVE-2026-82636
In current versions of Qubes OS, copying a file from the main system (dom0) to another virtual machine can unintentionally run system commands if the target VM is controlled by an attacker. This happe...
7.9
AshGraphQL may reveal hidden field names in error messages
CVE-2026-78693 EEF-CVE-2026-78693 GHSA-ppr2-g9h8-w7qp
Software that uses AshGraphQL can unintentionally include the names of hidden data fields in the error messages it sends back to users. This happens in versions from 1.9.0 up to but not including 1.11...
7.8
Ash GraphQL crashes on unknown node type
CVE-2026-81633 EEF-CVE-2026-81633 GHSA-mrgv-g7gf-r96h
The Ash GraphQL service can be forced to stop working when a user sends a specially crafted request that includes an unknown type identifier. This causes the system to throw an unhandled error and may...
7.8
AshSql can skip access checks and grant rights
CVE-2026-77454 EEF-CVE-2026-77454 GHSA-8v9m-8pxv-738c
If you are using AshSql version 0.4.1 up to but not including 0.7.1, a rule that both limits related data and checks a user’s permission may be ignored. This means a user could be allowed access simpl...
7.6
AJCloud cameras expose sensitive files to anyone
CVE-2026-56718
Older AJCloud camera firmware lets anyone on the network request files stored on the device without logging in. This can reveal passwords, Wi‑Fi keys, device serial numbers and other private settings....
8.7
Admidio before 5.0.12 lets anyone read private posts
CVE-2026-82657
The Admidio web tool (versions older than 5.0.12) does not properly block public access to its RSS feeds for forum topics and announcements. As a result, anyone on the internet can view the titles, fu...
8.7
Admidio before 5.0.12 can let outsiders read passwords
CVE-2026-82655
If you are using Admidio version older than 5.0.12, someone on the internet could trick the software into revealing the contents of your database, including user passwords. This can happen without nee...
8.7
WWBN AVideo allows unlimited login attempts
CVE-2026-82644
The AVideo platform does not count login tries from users whose browser does not send a identifying name, so an attacker can keep trying passwords without being blocked. This makes it easier to guess ...
8.7