Vulnerabilities (CVE)

Total 398697 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-19791 2026-08-14 9.0 HIGH 8.8 HIGH
A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2026-19841 2026-08-14 2.1 LOW 3.1 LOW
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-66471 2026-08-14 N/A 6.5 MEDIUM
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
CVE-2026-66466 2026-08-14 N/A 7.5 HIGH
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
CVE-2026-19762 2026-08-14 7.5 HIGH 7.3 HIGH
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched remotely. The exploit has been made public and could be used.
CVE-2026-66691 2026-08-14 N/A 9.8 CRITICAL
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
CVE-2026-73353 2026-08-14 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVE-2026-19837 2026-08-14 3.3 LOW 2.7 LOW
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
CVE-2026-66653 2026-08-14 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
CVE-2026-66698 2026-08-14 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
CVE-2026-73346 2026-08-14 N/A 7.6 HIGH
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-19838 2026-08-14 4.0 MEDIUM 4.3 MEDIUM
A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
CVE-2026-73357 2026-08-14 N/A 6.5 MEDIUM
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
CVE-2026-73344 2026-08-14 N/A 5.9 MEDIUM
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-19846 2026-08-14 9.0 HIGH 8.8 HIGH
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
CVE-2026-66658 2026-08-14 N/A 8.5 HIGH
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-19748 2026-08-14 2.6 LOW 3.7 LOW
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
CVE-2026-66472 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
CVE-2026-19757 2026-08-14 7.5 HIGH 7.3 HIGH
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-66689 2026-08-14 N/A 6.3 MEDIUM
Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.