Vulnerabilities (CVE)

Total 398677 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-66697 2026-08-14 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-19792 2026-08-14 9.0 HIGH 8.8 HIGH
A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-19815 2026-08-14 9.0 HIGH 8.8 HIGH
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2026-66660 2026-08-14 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
CVE-2026-19830 2026-08-14 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the argument USERLIMIT_GLOBAL results in allocation of resources. It is possible to launch the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-19747 2026-08-14 10.0 HIGH 9.8 CRITICAL
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.
CVE-2026-19710 2026-08-14 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVE-2026-73403 2026-08-14 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
CVE-2026-66656 2026-08-14 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
CVE-2026-66704 2026-08-14 N/A 7.2 HIGH
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
CVE-2026-19770 2026-08-14 4.3 MEDIUM 5.3 MEDIUM
A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-19829 2026-08-14 4.0 MEDIUM 4.3 MEDIUM
A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download Endpoint. The manipulation of the argument fileName results in path traversal. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-19845 2026-08-14 9.0 HIGH 8.8 HIGH
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-19746 2026-08-14 4.0 MEDIUM 4.3 MEDIUM
A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-19753 2026-08-14 7.5 HIGH 7.3 HIGH
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-66661 2026-08-14 N/A 7.7 HIGH
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVE-2026-73349 2026-08-14 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-66687 2026-08-14 N/A 6.5 MEDIUM
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
CVE-2026-66469 2026-08-14 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
CVE-2026-19791 2026-08-14 9.0 HIGH 8.8 HIGH
A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.