Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-13526

SourceCodester Class and Exam Timetabling System edit_class.php sql injection_CVE-2026-13526

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This ma...

SourceCodester Class and Exam Timetabling System 1.0 CVE
MEDIUM 5.3 CVE-2026-13525

CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection_CVE-2026-13525

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file applicat...

CodeAstro Human Resource Management System 1.0 CVE
MEDIUM 6.3 CVE-2026-13524

CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization_CVE-2026-13524

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/serv...

CherryHQ cherry-studio 1.9.0 CVE
MEDIUM 4.8 CVE-2026-13523

GPAC ISOBMFF base_encoding.c data amplification_CVE-2026-13523

A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF P...

n/a GPAC 26.02 CVE
LOW 2.3 CVE-2026-13511

VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization_CVE-2026-13511

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/s...

n/a VoltAgent 2.1.0 CVE
MEDIUM 6.3 CVE-2026-13510

SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/c...

SimStudioAI sim 0.6.0 CVE
MEDIUM 5.3 CVE-2026-13512

Databend Tenant client_session_manager.rs state_key authorization_CVE-2026-13512

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/s...

n/a Databend 1.2.881 CVE
HIGH 8.7 CVE-2026-13515

Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow_CVE-2026-13515

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServer...

Tenda JD12L 16.03.53.23 CVE
LOW 2.4 CVE-2026-13514

Chess Play and Learn App com.chess AndroidManifest.xml backup_CVE-2026-13514

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidM...

Chess Play and Learn App 4.9.0 CVE
LOW 2.3 CVE-2026-13513

MyScale MyScaleDB SegmentId.h getCacheKey data authenticity_CVE-2026-13513

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library...

MyScale MyScaleDB 1.0 CVE