Known Vulnerabilities for Ash Admin by Ash-project

Listed below are 10 of the newest known vulnerabilities associated with "Ash Admin" by "Ash-project".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-82722 json Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach th... Not Provided 2026-08-31 2026-08-31
CVE-2026-82681 json Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's strin... Not Provided 2026-08-31 2026-08-31
CVE-2026-82652 json SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view ba... Not Provided 2026-08-30 2026-08-30
CVE-2026-82651 json SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path an... Not Provided 2026-08-30 2026-08-30
CVE-2026-82647 json WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrator... Not Provided 2026-08-30 2026-08-30
CVE-2026-82636 json Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacke... Not Provided 2026-08-30 2026-08-30
CVE-2026-82607 json A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the functio... Not Provided 2026-08-31 2026-08-31
CVE-2026-82542 json A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /b... Not Provided 2026-08-30 2026-08-30
CVE-2026-82266 json Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthe... Not Provided 2026-08-28 2026-08-28
CVE-2026-82244 json Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated ad... Not Provided 2026-08-28 2026-08-28

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report