Total
398677 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66697 | 2026-08-14 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | |||||
| CVE-2026-19792 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2026-19815 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. | |||||
| CVE-2026-66660 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |||||
| CVE-2026-19830 | 2026-08-14 | 5.0 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the argument USERLIMIT_GLOBAL results in allocation of resources. It is possible to launch the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-19747 | 2026-08-14 | 10.0 HIGH | 9.8 CRITICAL | ||
| A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely. | |||||
| CVE-2026-19710 | 2026-08-14 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |||||
| CVE-2026-73403 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | |||||
| CVE-2026-66656 | 2026-08-14 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | |||||
| CVE-2026-66704 | 2026-08-14 | N/A | 7.2 HIGH | ||
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | |||||
| CVE-2026-19770 | 2026-08-14 | 4.3 MEDIUM | 5.3 MEDIUM | ||
| A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-19829 | 2026-08-14 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download Endpoint. The manipulation of the argument fileName results in path traversal. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2026-19845 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2026-19746 | 2026-08-14 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-19753 | 2026-08-14 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-66661 | 2026-08-14 | N/A | 7.7 HIGH | ||
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | |||||
| CVE-2026-73349 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |||||
| CVE-2026-66687 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. | |||||
| CVE-2026-66469 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | |||||
| CVE-2026-19791 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | |||||
