Total
398697 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19791 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-19841 | 2026-08-14 | 2.1 LOW | 3.1 LOW | ||
| A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-66471 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. | |||||
| CVE-2026-66466 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | |||||
| CVE-2026-19762 | 2026-08-14 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched remotely. The exploit has been made public and could be used. | |||||
| CVE-2026-66691 | 2026-08-14 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | |||||
| CVE-2026-73353 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | |||||
| CVE-2026-19837 | 2026-08-14 | 3.3 LOW | 2.7 LOW | ||
| A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." | |||||
| CVE-2026-66653 | 2026-08-14 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | |||||
| CVE-2026-66698 | 2026-08-14 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | |||||
| CVE-2026-73346 | 2026-08-14 | N/A | 7.6 HIGH | ||
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | |||||
| CVE-2026-19838 | 2026-08-14 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." | |||||
| CVE-2026-73357 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | |||||
| CVE-2026-73344 | 2026-08-14 | N/A | 5.9 MEDIUM | ||
| Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |||||
| CVE-2026-19846 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. | |||||
| CVE-2026-66658 | 2026-08-14 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | |||||
| CVE-2026-19748 | 2026-08-14 | 2.6 LOW | 3.7 LOW | ||
| A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. | |||||
| CVE-2026-66472 | 2026-08-14 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | |||||
| CVE-2026-19757 | 2026-08-14 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-66689 | 2026-08-14 | N/A | 6.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | |||||
