Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82694 | CRITICAL | 10.0 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation … | Aug 31, 2026 |
| CVE-2026-82693 | CRITICAL | 10.0 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a … | Aug 31, 2026 |
| CVE-2026-82692 | CRITICAL | 9.9 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of … | Aug 31, 2026 |
| CVE-2026-74010 | MEDIUM | 5.3 | Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14. | Aug 31, 2026 |
| CVE-2026-5956 | HIGH | 8.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects … | Aug 31, 2026 |
| CVE-2026-51667 | UNKNOWN | — | Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51666 | UNKNOWN | — | Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a … | Aug 31, 2026 |
| CVE-2026-12894 | HIGH | 8.8 | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue … | Aug 31, 2026 |
| CVE-2026-82797 | MEDIUM | 5.5 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51. | Aug 31, 2026 |
| CVE-2026-82691 | CRITICAL | 9.1 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the … | Aug 31, 2026 |
| CVE-2026-82690 | CRITICAL | 9.1 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. … | Aug 31, 2026 |
| CVE-2026-82689 | CRITICAL | 9.9 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the … | Aug 31, 2026 |
| CVE-2026-76984 | UNKNOWN | — | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names it wrote, … | Aug 31, 2026 |
| CVE-2026-76983 | UNKNOWN | — | Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every … | Aug 31, 2026 |
| CVE-2026-76982 | UNKNOWN | — | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it … | Aug 31, 2026 |
| CVE-2026-75802 | UNKNOWN | — | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML … | Aug 31, 2026 |
| CVE-2026-71378 | MEDIUM | 4.6 | ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default … | Aug 31, 2026 |
| CVE-2026-71257 | UNKNOWN | — | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request … | Aug 31, 2026 |
| CVE-2026-70449 | MEDIUM | 5.3 | Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF … | Aug 31, 2026 |
| CVE-2026-82881 | MEDIUM | 5.4 | Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and … | Aug 31, 2026 |
| CVE-2026-82880 | HIGH | 7.5 | YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. … | Aug 31, 2026 |
| CVE-2026-82879 | MEDIUM | 6.3 | DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid … | Aug 31, 2026 |
| CVE-2026-82878 | MEDIUM | 6.3 | DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging … | Aug 31, 2026 |
| CVE-2026-82877 | MEDIUM | 6.5 | ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated … | Aug 31, 2026 |
| CVE-2026-82876 | HIGH | 8.2 | Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can … | Aug 31, 2026 |