Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47870
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-19871 UNKNOWN Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee … Aug 14, 2026
CVE-2026-19830 MEDIUM 5.3 A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the … Aug 14, 2026
CVE-2026-19829 MEDIUM 4.3 A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download … Aug 14, 2026
CVE-2026-19828 MEDIUM 6.3 A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of … Aug 14, 2026
CVE-2026-19827 MEDIUM 5.3 A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. … Aug 14, 2026
CVE-2026-19768 HIGH 8.1 Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings … Aug 14, 2026
CVE-2026-73673 HIGH 8.8 Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication … Aug 14, 2026
CVE-2026-19870 UNKNOWN Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to … Aug 14, 2026
CVE-2026-19826 HIGH 7.3 A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The … Aug 14, 2026
CVE-2026-19825 HIGH 7.3 A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The … Aug 14, 2026
CVE-2026-19824 HIGH 8.8 A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the … Aug 14, 2026
CVE-2026-19823 HIGH 8.8 A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. … Aug 14, 2026
CVE-2026-73630 MEDIUM 5.8 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never … Aug 14, 2026
CVE-2026-73051 UNKNOWN actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated … Aug 14, 2026
CVE-2026-73049 MEDIUM 5.8 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when … Aug 14, 2026
CVE-2026-73048 MEDIUM 5.8 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can … Aug 14, 2026
CVE-2026-72859 HIGH 7.7 Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs … Aug 14, 2026
CVE-2026-72838 MEDIUM 6.5 FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. … Aug 14, 2026
CVE-2026-72837 HIGH 8.8 File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, … Aug 14, 2026
CVE-2026-72836 HIGH 8.1 FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root … Aug 14, 2026
CVE-2026-72835 MEDIUM 6.8 filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. … Aug 14, 2026
CVE-2026-72834 MEDIUM 4.3 filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest … Aug 14, 2026
CVE-2026-72833 HIGH 8.8 The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account … Aug 14, 2026
CVE-2026-72832 MEDIUM 5.4 Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and … Aug 14, 2026
CVE-2026-72831 HIGH 8.8 The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general … Aug 14, 2026