Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75460 | UNKNOWN | — | XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully … | Aug 31, 2026 |
| CVE-2026-75458 | HIGH | 8.1 | The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID … | Aug 31, 2026 |
| CVE-2026-71415 | UNKNOWN | — | Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload … | Aug 31, 2026 |
| CVE-2026-62993 | UNKNOWN | — | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release … | Aug 31, 2026 |
| CVE-2026-61641 | HIGH | 8.1 | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an … | Aug 31, 2026 |
| CVE-2026-61640 | UNKNOWN | — | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with … | Aug 31, 2026 |
| CVE-2026-61639 | UNKNOWN | — | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads … | Aug 31, 2026 |
| CVE-2026-61638 | UNKNOWN | — | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. … | Aug 31, 2026 |
| CVE-2026-54600 | UNKNOWN | — | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — … | Aug 31, 2026 |
| CVE-2026-54599 | UNKNOWN | — | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the … | Aug 31, 2026 |
| CVE-2026-54598 | HIGH | 7.5 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any … | Aug 31, 2026 |
| CVE-2026-54179 | MEDIUM | 4.4 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … | Aug 31, 2026 |
| CVE-2026-50199 | MEDIUM | 4.3 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential … | Aug 31, 2026 |
| CVE-2026-50198 | MEDIUM | 4.3 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to … | Aug 31, 2026 |
| CVE-2026-38577 | CRITICAL | 9.8 | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | Aug 31, 2026 |
| CVE-2025-63607 | MEDIUM | 6.1 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of … | Aug 31, 2026 |
| CVE-2026-82905 | MEDIUM | 6.3 | A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The … | Aug 31, 2026 |
| CVE-2026-82835 | MEDIUM | 5.4 | A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id … | Aug 31, 2026 |
| CVE-2026-82834 | MEDIUM | 5.4 | A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document … | Aug 31, 2026 |
| CVE-2026-82833 | MEDIUM | 6.3 | A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up … | Aug 31, 2026 |
| CVE-2026-81267 | MEDIUM | 5.4 | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled … | Aug 31, 2026 |
| CVE-2026-52730 | MEDIUM | 4.3 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in … | Aug 31, 2026 |
| CVE-2026-51740 | CRITICAL | 9.8 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51739 | UNKNOWN | — | Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51738 | UNKNOWN | — | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending … | Aug 31, 2026 |