Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42183
Total
3433
Critical
12465
High
12416
Medium
CVE ID Severity Score Description Published
CVE-2026-75460 UNKNOWN XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully … Aug 31, 2026
CVE-2026-75458 HIGH 8.1 The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID … Aug 31, 2026
CVE-2026-71415 UNKNOWN Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload … Aug 31, 2026
CVE-2026-62993 UNKNOWN Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release … Aug 31, 2026
CVE-2026-61641 HIGH 8.1 Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an … Aug 31, 2026
CVE-2026-61640 UNKNOWN Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with … Aug 31, 2026
CVE-2026-61639 UNKNOWN Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads … Aug 31, 2026
CVE-2026-61638 UNKNOWN Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. … Aug 31, 2026
CVE-2026-54600 UNKNOWN Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — … Aug 31, 2026
CVE-2026-54599 UNKNOWN Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the … Aug 31, 2026
CVE-2026-54598 HIGH 7.5 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any … Aug 31, 2026
CVE-2026-54179 MEDIUM 4.4 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … Aug 31, 2026
CVE-2026-50199 MEDIUM 4.3 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential … Aug 31, 2026
CVE-2026-50198 MEDIUM 4.3 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to … Aug 31, 2026
CVE-2026-38577 CRITICAL 9.8 Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. Aug 31, 2026
CVE-2025-63607 MEDIUM 6.1 TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of … Aug 31, 2026
CVE-2026-82905 MEDIUM 6.3 A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The … Aug 31, 2026
CVE-2026-82835 MEDIUM 5.4 A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id … Aug 31, 2026
CVE-2026-82834 MEDIUM 5.4 A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document … Aug 31, 2026
CVE-2026-82833 MEDIUM 6.3 A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up … Aug 31, 2026
CVE-2026-81267 MEDIUM 5.4 A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled … Aug 31, 2026
CVE-2026-52730 MEDIUM 4.3 Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in … Aug 31, 2026
CVE-2026-51740 CRITICAL 9.8 Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51739 UNKNOWN Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request … Aug 31, 2026
CVE-2026-51738 UNKNOWN Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending … Aug 31, 2026