Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45656
Total
3653
Critical
13500
High
13451
Medium
CVE ID Severity Score Description Published
CVE-2026-19924 CRITICAL 9.8 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper … Aug 16, 2026
CVE-2026-19923 MEDIUM 6.3 A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the … Aug 16, 2026
CVE-2026-19922 LOW 3.5 A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing … Aug 16, 2026
CVE-2026-19921 MEDIUM 6.3 A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of … Aug 16, 2026
CVE-2026-19920 MEDIUM 6.3 A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId … Aug 16, 2026
CVE-2026-19919 HIGH 7.3 A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation … Aug 16, 2026
CVE-2026-19918 MEDIUM 6.3 A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation … Aug 16, 2026
CVE-2026-19917 MEDIUM 6.3 A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a … Aug 15, 2026
CVE-2026-74767 UNKNOWN Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed … Aug 15, 2026
CVE-2026-74764 UNKNOWN Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly … Aug 15, 2026
CVE-2026-73055 MEDIUM 4.8 Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly … Aug 15, 2026
CVE-2026-73054 HIGH 7.5 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session … Aug 15, 2026
CVE-2026-73053 CRITICAL 9.0 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons … Aug 15, 2026
CVE-2026-73052 CRITICAL 9.0 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can … Aug 15, 2026
CVE-2026-73050 CRITICAL 9.0 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. … Aug 15, 2026
CVE-2026-73047 MEDIUM 6.2 siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature (introduced in v3.7.0-beta.1). The feature's template … Aug 15, 2026
CVE-2026-73046 CRITICAL 9.8 SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts … Aug 15, 2026
CVE-2026-73045 HIGH 7.5 SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. … Aug 15, 2026
CVE-2026-73044 CRITICAL 9.0 SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious … Aug 15, 2026
CVE-2026-73043 CRITICAL 9.0 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without … Aug 15, 2026
CVE-2026-73042 CRITICAL 9.0 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or … Aug 15, 2026
CVE-2026-73041 CRITICAL 9.0 SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation … Aug 15, 2026
CVE-2026-19916 LOW 3.5 A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation … Aug 15, 2026
CVE-2026-19906 LOW 3.7 A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. … Aug 15, 2026
CVE-2026-19905 HIGH 7.3 A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes … Aug 15, 2026