Total
398517 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-73184 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | |||||
| CVE-2026-32444 | 2026-08-20 | N/A | 9.9 CRITICAL | ||
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | |||||
| CVE-2026-73360 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | |||||
| CVE-2026-19999 | 2026-08-20 | 7.5 HIGH | 6.3 MEDIUM | ||
| A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone Transformation Key Parser. The manipulation of the argument transmatrix_count/pcBoneTransforms leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is 50d767984e78d51b53e2020fdf0967fd624bc377. It is recommended to apply a patch to fix this issue. | |||||
| CVE-2026-28567 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | |||||
| CVE-2026-73352 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | |||||
| CVE-2026-19965 | 2026-08-20 | 2.6 LOW | 3.7 LOW | ||
| A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component. | |||||
| CVE-2026-73339 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | |||||
| CVE-2026-73994 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | |||||
| CVE-2026-74015 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | |||||
| CVE-2026-66620 | 2026-08-20 | N/A | 7.2 HIGH | ||
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | |||||
| CVE-2026-74843 | 2026-08-20 | 10.0 HIGH | 10.0 CRITICAL | ||
| A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure. | |||||
| CVE-2026-75984 | 2026-08-20 | 6.5 MEDIUM | 7.4 HIGH | ||
| A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of the argument Hostname results in command injection. The attack can be launched remotely. The exploit is now public and may be used. | |||||
| CVE-2026-75088 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument delid can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2026-19959 | 2026-08-20 | 9.0 HIGH | 9.9 CRITICAL | ||
| A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-75012 | 2026-08-20 | 6.8 MEDIUM | 6.5 MEDIUM | ||
| A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Password Configuration Handler. The manipulation leads to null pointer dereference. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-73358 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | |||||
| CVE-2026-28192 | 2026-08-20 | N/A | 9.6 CRITICAL | ||
| Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | |||||
| CVE-2026-73365 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | |||||
| CVE-2026-73393 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | |||||
