CVE detail
CVE-2026-19975
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://vuldb.com/vuln/391154/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 3:16 AM - https://vuldb.com/vuln/391154vuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 3:16 AM - https://vuldb.com/submit/873734vuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 3:16 AM - https://vuldb.com/cve/CVE-2026-19975vuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 3:16 AM No excerpt available.
Exploitgithub.comAug 17, 2026, 3:16 AMNo excerpt available.
Exploitgithub.comAug 17, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16082CVSS 1.9 · Low
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation…
- CVE-2026-53518CVSS 7.6 · High
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorizati…
- CVE-2026-53517CVSS 8.1 · High
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refre…
- CVE-2026-13502CVSS 1.1 · Low
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/Gram…
- CVE-2026-52991CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressure write A potential race condition exists between pressur…
- CVE-2026-5947CVSS 7.5 · High
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to valida…