Total
397465 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-75331 | 2026-08-31 | N/A | 4.6 MEDIUM | ||
| tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server. | |||||
| CVE-2026-30062 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU. | |||||
| CVE-2026-67921 | 2026-08-31 | N/A | 9.3 CRITICAL | ||
| Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code. | |||||
| CVE-2026-67965 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function | |||||
| CVE-2026-75330 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound. | |||||
| CVE-2026-30057 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request. | |||||
| CVE-2026-52480 | 2026-08-31 | N/A | 6.5 MEDIUM | ||
| An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service | |||||
| CVE-2026-67920 | 2026-08-31 | N/A | 8.8 HIGH | ||
| An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components | |||||
| CVE-2026-75329 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential. | |||||
| CVE-2026-52608 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | |||||
| CVE-2026-67678 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | |||||
| CVE-2026-71675 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c | |||||
| CVE-2026-67966 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access. | |||||
| CVE-2026-75332 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). | |||||
| CVE-2026-50770 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. | |||||
| CVE-2026-52610 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint. | |||||
| CVE-2026-30050 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request. | |||||
| CVE-2026-42163 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage. | |||||
| CVE-2026-52609 | 2026-08-31 | N/A | 6.1 MEDIUM | ||
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php. | |||||
| CVE-2026-75333 | 2026-08-31 | N/A | 7.5 HIGH | ||
| yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation. | |||||
