Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82833 | MEDIUM | 6.3 | A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up … | Aug 31, 2026 |
| CVE-2026-81267 | MEDIUM | 5.4 | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled … | Aug 31, 2026 |
| CVE-2026-52730 | MEDIUM | 4.3 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in … | Aug 31, 2026 |
| CVE-2026-51740 | CRITICAL | 9.8 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51739 | UNKNOWN | — | Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51738 | UNKNOWN | — | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending … | Aug 31, 2026 |
| CVE-2026-51737 | MEDIUM | 5.3 | Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51736 | CRITICAL | 9.1 | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51735 | HIGH | 7.5 | Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51734 | CRITICAL | 9.8 | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51733 | UNKNOWN | — | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51732 | MEDIUM | 5.3 | Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51731 | CRITICAL | 9.1 | Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-14697 | MEDIUM | 6.5 | net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and … | Aug 31, 2026 |
| CVE-2026-13732 | HIGH | 7.8 | A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that … | Aug 31, 2026 |
| CVE-2026-83497 | HIGH | 8.8 | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to … | Aug 31, 2026 |
| CVE-2026-82821 | MEDIUM | 4.3 | A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF … | Aug 31, 2026 |
| CVE-2026-82820 | MEDIUM | 4.3 | A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The … | Aug 31, 2026 |
| CVE-2026-82818 | MEDIUM | 6.3 | A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing … | Aug 31, 2026 |
| CVE-2026-72001 | HIGH | 8.1 | Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the … | Aug 31, 2026 |
| CVE-2026-53553 | HIGH | 7.7 | Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File … | Aug 31, 2026 |
| CVE-2026-53552 | CRITICAL | 9.6 | Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row … | Aug 31, 2026 |
| CVE-2026-53508 | UNKNOWN | — | oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not … | Aug 31, 2026 |
| CVE-2026-53507 | UNKNOWN | — | oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff … | Aug 31, 2026 |
| CVE-2026-14696 | MEDIUM | 6.5 | When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For frames that must … | Aug 31, 2026 |