Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42239
Total
3441
Critical
12474
High
12431
Medium
CVE ID Severity Score Description Published
CVE-2026-78077 UNKNOWN Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and … Aug 31, 2026
CVE-2026-78076 UNKNOWN Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed … Aug 31, 2026
CVE-2026-78075 UNKNOWN Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized … Aug 31, 2026
CVE-2026-78074 UNKNOWN Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed … Aug 31, 2026
CVE-2026-76986 MEDIUM 6.1 Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — … Aug 31, 2026
CVE-2026-76985 UNKNOWN Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and … Aug 31, 2026
CVE-2026-76763 HIGH 7.5 A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An … Aug 31, 2026
CVE-2026-51681 CRITICAL 9.1 Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51680 CRITICAL 9.1 Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51679 CRITICAL 9.1 Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request … Aug 31, 2026
CVE-2026-51678 UNKNOWN Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51677 UNKNOWN Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request … Aug 31, 2026
CVE-2026-51676 UNKNOWN Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51675 UNKNOWN Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51674 UNKNOWN Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request … Aug 31, 2026
CVE-2026-51673 UNKNOWN Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request … Aug 31, 2026
CVE-2026-51672 UNKNOWN Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST … Aug 31, 2026
CVE-2026-51671 UNKNOWN Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted … Aug 31, 2026
CVE-2026-51670 UNKNOWN Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending … Aug 31, 2026
CVE-2026-51669 UNKNOWN Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST … Aug 31, 2026
CVE-2026-51668 UNKNOWN Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to … Aug 31, 2026
CVE-2026-19702 HIGH 7.8 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows … Aug 31, 2026
CVE-2026-19616 HIGH 7.5 Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2. Aug 31, 2026
CVE-2026-82696 MEDIUM 6.3 A weakness has been identified in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_searchfrm.php. This manipulation … Aug 31, 2026
CVE-2026-82695 CRITICAL 10.0 A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The … Aug 31, 2026