| CVE-2026-71257 | HIGH | 7.5 | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart reques… | 2026-08-31 |
| CVE-2026-71378 | MEDIUM | 4.6 | ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by reje… | 2026-08-31 |
| CVE-2026-75802 | MEDIUM | 5.4 | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the dis… | 2026-08-31 |
| CVE-2026-76982 | MEDIUM | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.markup.html.f… | 2026-08-31 |
| CVE-2026-76983 | MEDIUM | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
The tag is provi… | 2026-08-31 |
| CVE-2026-76984 | MEDIUM | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.markup.head.M… | 2026-08-31 |
| CVE-2026-82689 | CRITICAL | 9.9 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an… | 2026-08-31 |
| CVE-2026-82690 | CRITICAL | 9.1 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unk… | 2026-08-31 |
| CVE-2026-82691 | CRITICAL | 9.1 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by … | 2026-08-31 |
| CVE-2026-82797 | MEDIUM | 5.5 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payload… | 2026-08-31 |
| CVE-2026-12894 | HIGH | 8.8 | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML p… | 2026-08-31 |
| CVE-2026-51666 | MEDIUM | 4.3 | Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica… | 2026-08-31 |
| CVE-2026-51667 | MEDIUM | 4.3 | Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe… | 2026-08-31 |
| CVE-2026-5956 | HIGH | 8.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara H… | 2026-08-31 |
| CVE-2026-74010 | MEDIUM | 5.3 | Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Acce… | 2026-08-31 |
| CVE-2026-82692 | CRITICAL | 9.9 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the f… | 2026-08-31 |
| CVE-2026-82693 | CRITICAL | 10.0 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelne… | 2026-08-31 |
| CVE-2026-82694 | CRITICAL | 10.0 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHand… | 2026-08-31 |
| CVE-2026-82695 | CRITICAL | 10.0 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /go… | 2026-08-31 |
| CVE-2026-82696 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. The affected element is an unkn… | 2026-08-31 |
| CVE-2026-19616 | HIGH | 7.5 | Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Prop… | 2026-08-31 |
| CVE-2026-19702 | HIGH | 7.8 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜ… | 2026-08-31 |
| CVE-2026-51668 | HIGH | 7.5 | Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti… | 2026-08-31 |
| CVE-2026-51669 | CRITICAL | 9.1 | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate… | 2026-08-31 |
| CVE-2026-51670 | CRITICAL | 9.8 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti… | 2026-08-31 |
| CVE-2026-51671 | HIGH | 7.5 | Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un… | 2026-08-31 |
| CVE-2026-51672 | CRITICAL | 9.1 | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic… | 2026-08-31 |
| CVE-2026-51673 | HIGH | 7.5 | Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated… | 2026-08-31 |
| CVE-2026-51674 | CRITICAL | 9.8 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti… | 2026-08-31 |
| CVE-2026-51675 | CRITICAL | 9.1 | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat… | 2026-08-31 |
| CVE-2026-51676 | CRITICAL | 9.1 | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth… | 2026-08-31 |
| CVE-2026-51677 | CRITICAL | 9.1 | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate… | 2026-08-31 |
| CVE-2026-51678 | MEDIUM | 4.3 | Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica… | 2026-08-31 |
| CVE-2026-51679 | CRITICAL | 9.1 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti… | 2026-08-31 |
| CVE-2026-51680 | CRITICAL | 9.1 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated… | 2026-08-31 |
| CVE-2026-51681 | CRITICAL | 9.1 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica… | 2026-08-31 |
| CVE-2026-76763 | HIGH | 7.5 | A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the… | 2026-08-31 |
| CVE-2026-76985 | MEDIUM | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.extensions.ma… | 2026-08-31 |
| CVE-2026-76986 | MEDIUM | 6.1 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.markup.html.f… | 2026-08-31 |
| CVE-2026-78074 | NA | N/A | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange… | 2026-08-31 |
| CVE-2026-78075 | NA | N/A | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate… | 2026-08-31 |
| CVE-2026-78076 | NA | N/A | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Heli… | 2026-08-31 |
| CVE-2026-78077 | NA | N/A | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed In… | 2026-08-31 |
| CVE-2026-78078 | NA | N/A | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2… | 2026-08-31 |
| CVE-2026-78079 | NA | N/A | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Ret… | 2026-08-31 |
| CVE-2026-82217 | HIGH | 8.8 | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeF… | 2026-08-31 |
| CVE-2026-82697 | LOW | 3.7 | A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb42… | 2026-08-31 |
| CVE-2026-82698 | MEDIUM | 5.3 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4… | 2026-08-31 |
| CVE-2026-82699 | LOW | 2.7 | A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. T… | 2026-08-31 |
| CVE-2026-82700 | MEDIUM | 4.3 | A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an un… | 2026-08-31 |