| CVE-2026-82820 | MEDIUM | 4.3 | A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.… | 2026-08-31 |
| CVE-2026-82821 | MEDIUM | 4.3 | A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_obje… | 2026-08-31 |
| CVE-2026-83497 | HIGH | 8.8 | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin… | 2026-08-31 |
| CVE-2026-13732 | HIGH | 7.8 | A flaw was found in GDB's STABS debug format parser. The
read_member_functions() function in gdb/stabsread.c c… | 2026-08-31 |
| CVE-2026-14697 | MEDIUM | 6.5 | net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When … | 2026-08-31 |
| CVE-2026-51731 | CRITICAL | 9.1 | Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate… | 2026-08-31 |
| CVE-2026-51732 | MEDIUM | 5.3 | Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth… | 2026-08-31 |
| CVE-2026-51733 | NA | N/A | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent… | 2026-08-31 |
| CVE-2026-51734 | CRITICAL | 9.8 | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe… | 2026-08-31 |
| CVE-2026-51735 | HIGH | 7.5 | Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate… | 2026-08-31 |
| CVE-2026-51736 | CRITICAL | 9.1 | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat… | 2026-08-31 |
| CVE-2026-51737 | MEDIUM | 5.3 | Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth… | 2026-08-31 |
| CVE-2026-51738 | NA | N/A | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent… | 2026-08-31 |
| CVE-2026-51739 | MEDIUM | 5.9 | Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau… | 2026-08-31 |
| CVE-2026-51740 | CRITICAL | 9.8 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat… | 2026-08-31 |
| CVE-2026-52730 | MEDIUM | 4.3 | Xibo is an open source digital signage platform with a web content management system and Windows display playe… | 2026-08-31 |
| CVE-2026-81267 | MEDIUM | 5.4 | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to dis… | 2026-08-31 |
| CVE-2026-82833 | MEDIUM | 6.3 | A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and … | 2026-08-31 |
| CVE-2026-82834 | MEDIUM | 5.4 | A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners… | 2026-08-31 |
| CVE-2026-82835 | MEDIUM | 5.4 | A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of… | 2026-08-31 |
| CVE-2026-82905 | MEDIUM | 6.3 | A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file s… | 2026-08-31 |
| CVE-2025-63607 | MEDIUM | 6.1 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id p… | 2026-08-31 |
| CVE-2026-38577 | CRITICAL | 9.8 | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root … | 2026-08-31 |
| CVE-2026-50198 | MEDIUM | 4.3 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticate… | 2026-08-31 |
| CVE-2026-50199 | MEDIUM | 4.3 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/curre… | 2026-08-31 |
| CVE-2026-54179 | MEDIUM | 4.4 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa… | 2026-08-31 |
| CVE-2026-54598 | HIGH | 7.5 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/mi… | 2026-08-31 |
| CVE-2026-54599 | NA | N/A | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php gener… | 2026-08-31 |
| CVE-2026-54600 | NA | N/A | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/im… | 2026-08-31 |
| CVE-2026-61638 | NA | N/A | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints… | 2026-08-31 |
| CVE-2026-61639 | NA | N/A | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints… | 2026-08-31 |
| CVE-2026-61640 | NA | N/A | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configure… | 2026-08-31 |
| CVE-2026-61641 | HIGH | 8.1 | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.… | 2026-08-31 |
| CVE-2026-62993 | NA | N/A | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application l… | 2026-08-31 |
| CVE-2026-71415 | NA | N/A | Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handl… | 2026-08-31 |
| CVE-2026-75458 | HIGH | 8.1 | The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 cont… | 2026-08-31 |
| CVE-2026-75460 | MEDIUM | 6.5 | XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interfac… | 2026-08-31 |
| CVE-2026-75592 | NA | N/A | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Ki… | 2026-08-31 |
| CVE-2026-75594 | NA | N/A | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Ki… | 2026-08-31 |
| CVE-2026-79407 | HIGH | 7.5 | A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary file… | 2026-08-31 |
| CVE-2026-79408 | CRITICAL | 9.8 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via th… | 2026-08-31 |
| CVE-2026-79483 | MEDIUM | 5.3 | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat… | 2026-08-31 |
| CVE-2026-81278 | MEDIUM | 5.4 | Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Con… | 2026-08-31 |
| CVE-2026-81280 | MEDIUM | 6.5 | Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versi… | 2026-08-31 |
| CVE-2026-81287 | HIGH | 8.5 | Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.… | 2026-08-31 |
| CVE-2026-81290 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.… | 2026-08-31 |
| CVE-2026-81291 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.… | 2026-08-31 |
| CVE-2026-81293 | CRITICAL | 9.3 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.… | 2026-08-31 |
| CVE-2026-81296 | HIGH | 7.5 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.… | 2026-08-31 |
| CVE-2026-81297 | HIGH | 7.5 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.… | 2026-08-31 |