CVE IDSeverityCVSSDescriptionDate
CVE-2026-82820MEDIUM4.3A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.…2026-08-31
CVE-2026-82821MEDIUM4.3A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_obje…2026-08-31
CVE-2026-83497HIGH8.8Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin…2026-08-31
CVE-2026-13732HIGH7.8A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c c…2026-08-31
CVE-2026-14697MEDIUM6.5net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When …2026-08-31
CVE-2026-51731CRITICAL9.1Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate…2026-08-31
CVE-2026-51732MEDIUM5.3Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth…2026-08-31
CVE-2026-51733NAN/AIncorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent…2026-08-31
CVE-2026-51734CRITICAL9.8Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe…2026-08-31
CVE-2026-51735HIGH7.5Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate…2026-08-31
CVE-2026-51736CRITICAL9.1Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat…2026-08-31
CVE-2026-51737MEDIUM5.3Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth…2026-08-31
CVE-2026-51738NAN/AIncorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent…2026-08-31
CVE-2026-51739MEDIUM5.9Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau…2026-08-31
CVE-2026-51740CRITICAL9.8Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat…2026-08-31
CVE-2026-52730MEDIUM4.3Xibo is an open source digital signage platform with a web content management system and Windows display playe…2026-08-31
CVE-2026-81267MEDIUM5.4A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to dis…2026-08-31
CVE-2026-82833MEDIUM6.3A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and …2026-08-31
CVE-2026-82834MEDIUM5.4A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners…2026-08-31
CVE-2026-82835MEDIUM5.4A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of…2026-08-31
CVE-2026-82905MEDIUM6.3A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file s…2026-08-31
CVE-2025-63607MEDIUM6.1TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id p…2026-08-31
CVE-2026-38577CRITICAL9.8Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root …2026-08-31
CVE-2026-50198MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticate…2026-08-31
CVE-2026-50199MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/curre…2026-08-31
CVE-2026-54179MEDIUM4.4backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…2026-08-31
CVE-2026-54598HIGH7.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/mi…2026-08-31
CVE-2026-54599NAN/AWallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php gener…2026-08-31
CVE-2026-54600NAN/AWallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/im…2026-08-31
CVE-2026-61638NAN/AWallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints…2026-08-31
CVE-2026-61639NAN/AWallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints…2026-08-31
CVE-2026-61640NAN/AWallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configure…2026-08-31
CVE-2026-61641HIGH8.1Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.…2026-08-31
CVE-2026-62993NAN/ASmarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application l…2026-08-31
CVE-2026-71415NAN/AKirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handl…2026-08-31
CVE-2026-75458HIGH8.1The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 cont…2026-08-31
CVE-2026-75460MEDIUM6.5XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interfac…2026-08-31
CVE-2026-75592NAN/AKirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Ki…2026-08-31
CVE-2026-75594NAN/AKirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Ki…2026-08-31
CVE-2026-79407HIGH7.5A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary file…2026-08-31
CVE-2026-79408CRITICAL9.8An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via th…2026-08-31
CVE-2026-79483MEDIUM5.3FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat…2026-08-31
CVE-2026-81278MEDIUM5.4Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Con…2026-08-31
CVE-2026-81280MEDIUM6.5Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versi…2026-08-31
CVE-2026-81287HIGH8.5Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.…2026-08-31
CVE-2026-81290HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.…2026-08-31
CVE-2026-81291HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.…2026-08-31
CVE-2026-81293CRITICAL9.3Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.…2026-08-31
CVE-2026-81296HIGH7.5Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.…2026-08-31
CVE-2026-81297HIGH7.5Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.…2026-08-31
20 / 7715