Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78422 | UNKNOWN | — | Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority … | Aug 31, 2026 |
| CVE-2026-66047 | HIGH | 8.1 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing … | Aug 31, 2026 |
| CVE-2026-63083 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 31, 2026 |
| CVE-2026-59111 | CRITICAL | 9.3 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an … | Aug 31, 2026 |
| CVE-2026-51697 | UNKNOWN | — | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51696 | UNKNOWN | — | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51695 | UNKNOWN | — | Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51694 | UNKNOWN | — | Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted … | Aug 31, 2026 |
| CVE-2026-51693 | UNKNOWN | — | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51692 | UNKNOWN | — | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted … | Aug 31, 2026 |
| CVE-2026-51691 | UNKNOWN | — | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted … | Aug 31, 2026 |
| CVE-2026-51690 | UNKNOWN | — | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51689 | UNKNOWN | — | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51688 | UNKNOWN | — | Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) … | Aug 31, 2026 |
| CVE-2026-51687 | UNKNOWN | — | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted … | Aug 31, 2026 |
| CVE-2026-51686 | UNKNOWN | — | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51684 | UNKNOWN | — | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51683 | UNKNOWN | — | Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-82700 | MEDIUM | 4.3 | A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component … | Aug 31, 2026 |
| CVE-2026-82699 | LOW | 2.7 | A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component … | Aug 31, 2026 |
| CVE-2026-82698 | MEDIUM | 5.3 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use … | Aug 31, 2026 |
| CVE-2026-82697 | LOW | 3.7 | A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without … | Aug 31, 2026 |
| CVE-2026-82217 | HIGH | 8.8 | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) … | Aug 31, 2026 |
| CVE-2026-78079 | UNKNOWN | — | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without … | Aug 31, 2026 |
| CVE-2026-78078 | UNKNOWN | — | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension … | Aug 31, 2026 |