Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47180
Total
3801
Critical
14071
High
13766
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19790 | HIGH | 8.8 | A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web … | Aug 14, 2026 |
| CVE-2026-19789 | HIGH | 8.8 | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. … | Aug 14, 2026 |
| CVE-2026-19788 | HIGH | 8.8 | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The … | Aug 14, 2026 |
| CVE-2026-19787 | MEDIUM | 4.7 | A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the … | Aug 14, 2026 |
| CVE-2026-19786 | MEDIUM | 4.3 | A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in … | Aug 14, 2026 |
| CVE-2026-19785 | MEDIUM | 6.3 | A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical … | Aug 14, 2026 |
| CVE-2026-19784 | MEDIUM | 4.3 | A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. … | Aug 14, 2026 |
| CVE-2026-18109 | HIGH | 7.2 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 … | Aug 14, 2026 |
| CVE-2026-19771 | HIGH | 7.2 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation … | Aug 14, 2026 |
| CVE-2026-19770 | MEDIUM | 5.3 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. … | Aug 14, 2026 |
| CVE-2026-19767 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of … | Aug 14, 2026 |
| CVE-2026-19765 | MEDIUM | 6.3 | A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the function loadSource of the file src/utils/swagger-parser.ts of the component fetch_swagger. Performing … | Aug 14, 2026 |
| CVE-2026-19764 | HIGH | 7.3 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such … | Aug 14, 2026 |
| CVE-2026-19763 | LOW | 3.8 | A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. … | Aug 14, 2026 |
| CVE-2026-19762 | HIGH | 7.3 | A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. … | Aug 14, 2026 |
| CVE-2026-19761 | MEDIUM | 4.7 | A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. The manipulation … | Aug 14, 2026 |
| CVE-2026-19758 | HIGH | 7.3 | A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. … | Aug 14, 2026 |
| CVE-2026-19757 | HIGH | 7.3 | A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing … | Aug 14, 2026 |
| CVE-2026-3883 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 13, 2026 |
| CVE-2026-19756 | MEDIUM | 6.3 | A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. … | Aug 13, 2026 |
| CVE-2026-19753 | HIGH | 7.3 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing … | Aug 13, 2026 |
| CVE-2026-18532 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 13, 2026 |
| CVE-2026-73843 | CRITICAL | 9.6 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener … | Aug 13, 2026 |
| CVE-2026-73842 | CRITICAL | 9.0 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener … | Aug 13, 2026 |
| CVE-2026-73841 | HIGH | 8.8 | OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query … | Aug 13, 2026 |