Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47870
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19813 | HIGH | 8.8 | A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation … | Aug 14, 2026 |
| CVE-2026-19812 | HIGH | 8.8 | A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of … | Aug 14, 2026 |
| CVE-2026-19794 | HIGH | 7.2 | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and … | Aug 14, 2026 |
| CVE-2026-19811 | HIGH | 8.8 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. … | Aug 14, 2026 |
| CVE-2026-19617 | MEDIUM | 5.5 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could … | Aug 14, 2026 |
| CVE-2026-18039 | HIGH | 8.1 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register … | Aug 14, 2026 |
| CVE-2026-16810 | MEDIUM | 6.5 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection … | Aug 14, 2026 |
| CVE-2026-16739 | MEDIUM | 5.9 | The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, … | Aug 14, 2026 |
| CVE-2026-15205 | HIGH | 8.6 | The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, … | Aug 14, 2026 |
| CVE-2026-14290 | MEDIUM | 6.8 | The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users … | Aug 14, 2026 |
| CVE-2026-12949 | CRITICAL | 9.8 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This … | Aug 14, 2026 |
| CVE-2026-12743 | MEDIUM | 4.9 | The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions … | Aug 14, 2026 |
| CVE-2026-19792 | HIGH | 8.8 | A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd … | Aug 14, 2026 |
| CVE-2026-19791 | HIGH | 8.8 | A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component … | Aug 14, 2026 |
| CVE-2025-10308 | MEDIUM | 4.3 | The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to … | Aug 14, 2026 |
| CVE-2026-19790 | HIGH | 8.8 | A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web … | Aug 14, 2026 |
| CVE-2026-19789 | HIGH | 8.8 | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. … | Aug 14, 2026 |
| CVE-2026-19788 | HIGH | 8.8 | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The … | Aug 14, 2026 |
| CVE-2026-19787 | MEDIUM | 4.7 | A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the … | Aug 14, 2026 |
| CVE-2026-19786 | MEDIUM | 4.3 | A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in … | Aug 14, 2026 |
| CVE-2026-19785 | MEDIUM | 6.3 | A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical … | Aug 14, 2026 |
| CVE-2026-19784 | MEDIUM | 4.3 | A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. … | Aug 14, 2026 |
| CVE-2026-18109 | HIGH | 7.2 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 … | Aug 14, 2026 |
| CVE-2026-19771 | HIGH | 7.2 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation … | Aug 14, 2026 |
| CVE-2026-19770 | MEDIUM | 5.3 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. … | Aug 14, 2026 |