Vulnerabilities (CVE)

Total 398795 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18784 2026-08-12 4.3 MEDIUM 5.3 MEDIUM
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.
CVE-2026-18974 2026-08-12 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-18897 2026-08-12 9.0 HIGH 8.8 HIGH
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-65554 2026-08-12 N/A 7.1 HIGH
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
CVE-2026-18685 2026-08-12 10.0 HIGH 9.8 CRITICAL
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
CVE-2026-66710 2026-08-12 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-65542 2026-08-12 N/A 8.8 HIGH
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-65549 2026-08-12 N/A 7.2 HIGH
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-18895 2026-08-12 9.0 HIGH 8.8 HIGH
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-65547 2026-08-12 N/A 8.5 HIGH
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
CVE-2026-18686 2026-08-12 10.0 HIGH 9.8 CRITICAL
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
CVE-2026-18990 2026-08-12 7.5 HIGH 7.3 HIGH
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-18788 2026-08-12 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-66705 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2026-18770 2026-08-12 7.5 HIGH 7.3 HIGH
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-66688 2026-08-12 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-66447 2026-08-12 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
CVE-2026-18647 2026-08-12 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-18959 2026-08-12 5.5 MEDIUM 5.4 MEDIUM
A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-65559 2026-08-12 N/A 7.2 HIGH
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.