Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47180
Total
3801
Critical
14071
High
13766
Medium
CVE ID Severity Score Description Published
CVE-2026-72814 UNKNOWN The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the … Aug 14, 2026
CVE-2026-72813 UNKNOWN actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set … Aug 14, 2026
CVE-2026-72812 MEDIUM 6.5 SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke … Aug 14, 2026
CVE-2026-72811 CRITICAL 10.0 SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) … Aug 14, 2026
CVE-2026-72810 HIGH 8.6 SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a … Aug 14, 2026
CVE-2026-19822 HIGH 8.8 A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation … Aug 14, 2026
CVE-2025-71405 UNKNOWN chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can … Aug 14, 2026
CVE-2026-19821 HIGH 8.8 A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. … Aug 14, 2026
CVE-2026-19815 HIGH 8.8 A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. … Aug 14, 2026
CVE-2026-19814 HIGH 8.8 A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of … Aug 14, 2026
CVE-2026-19813 HIGH 8.8 A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation … Aug 14, 2026
CVE-2026-19812 HIGH 8.8 A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of … Aug 14, 2026
CVE-2026-19794 HIGH 7.2 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and … Aug 14, 2026
CVE-2026-19811 HIGH 8.8 A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. … Aug 14, 2026
CVE-2026-19617 MEDIUM 5.5 A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could … Aug 14, 2026
CVE-2026-18039 HIGH 8.1 The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register … Aug 14, 2026
CVE-2026-16810 MEDIUM 6.5 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection … Aug 14, 2026
CVE-2026-16739 MEDIUM 5.9 The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, … Aug 14, 2026
CVE-2026-15205 HIGH 8.6 The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, … Aug 14, 2026
CVE-2026-14290 MEDIUM 6.8 The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users … Aug 14, 2026
CVE-2026-12949 CRITICAL 9.8 The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This … Aug 14, 2026
CVE-2026-12743 MEDIUM 4.9 The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions … Aug 14, 2026
CVE-2026-19792 HIGH 8.8 A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd … Aug 14, 2026
CVE-2026-19791 HIGH 8.8 A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component … Aug 14, 2026
CVE-2025-10308 MEDIUM 4.3 The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to … Aug 14, 2026