Total
398517 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-74006 | 2026-08-20 | N/A | 4.3 MEDIUM | ||
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | |||||
| CVE-2026-75877 | 2026-08-20 | 9.0 HIGH | 9.9 CRITICAL | ||
| A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. | |||||
| CVE-2026-76004 | 2026-08-20 | 9.0 HIGH | 9.9 CRITICAL | ||
| A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-75151 | 2026-08-20 | 5.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. | |||||
| CVE-2026-73362 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | |||||
| CVE-2026-74004 | 2026-08-20 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | |||||
| CVE-2026-66646 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. | |||||
| CVE-2026-73380 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | |||||
| CVE-2026-32464 | 2026-08-20 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | |||||
| CVE-2026-19901 | 2026-08-20 | 7.6 HIGH | 8.1 HIGH | ||
| A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-73378 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | |||||
| CVE-2026-73995 | 2026-08-20 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Authentication in User Registration <= 5.2.6 versions. | |||||
| CVE-2026-66634 | 2026-08-20 | N/A | 4.3 MEDIUM | ||
| Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. | |||||
| CVE-2026-19896 | 2026-08-20 | 2.6 LOW | 3.7 LOW | ||
| A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance. | |||||
| CVE-2026-19898 | 2026-08-20 | 2.6 LOW | 3.7 LOW | ||
| A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made public and could be used. Upgrading to version 1.147.0 is recommended to address this issue. The patch is named 119ba0fb5be8024d50c5ba946599b2e69e8803ea. Upgrading the affected component is recommended. | |||||
| CVE-2026-19916 | 2026-08-20 | 4.0 MEDIUM | 3.5 LOW | ||
| A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |||||
| CVE-2026-73338 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | |||||
| CVE-2026-74842 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component Image-Toolkit-MCP-Server. Performing a manipulation of the argument image_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-75094 | 2026-08-20 | 8.3 HIGH | 9.1 CRITICAL | ||
| A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |||||
| CVE-2026-19928 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended. | |||||
