Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78077 | UNKNOWN | — | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and … | Aug 31, 2026 |
| CVE-2026-78076 | UNKNOWN | — | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed … | Aug 31, 2026 |
| CVE-2026-78075 | UNKNOWN | — | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized … | Aug 31, 2026 |
| CVE-2026-78074 | UNKNOWN | — | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed … | Aug 31, 2026 |
| CVE-2026-76986 | MEDIUM | 6.1 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — … | Aug 31, 2026 |
| CVE-2026-76985 | UNKNOWN | — | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and … | Aug 31, 2026 |
| CVE-2026-76763 | HIGH | 7.5 | A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An … | Aug 31, 2026 |
| CVE-2026-51681 | CRITICAL | 9.1 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51680 | CRITICAL | 9.1 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51679 | CRITICAL | 9.1 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51678 | UNKNOWN | — | Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51677 | UNKNOWN | — | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51676 | UNKNOWN | — | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51675 | UNKNOWN | — | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51674 | UNKNOWN | — | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51673 | UNKNOWN | — | Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51672 | UNKNOWN | — | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51671 | UNKNOWN | — | Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted … | Aug 31, 2026 |
| CVE-2026-51670 | UNKNOWN | — | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending … | Aug 31, 2026 |
| CVE-2026-51669 | UNKNOWN | — | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51668 | UNKNOWN | — | Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-19702 | HIGH | 7.8 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows … | Aug 31, 2026 |
| CVE-2026-19616 | HIGH | 7.5 | Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2. | Aug 31, 2026 |
| CVE-2026-82696 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_searchfrm.php. This manipulation … | Aug 31, 2026 |
| CVE-2026-82695 | CRITICAL | 10.0 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The … | Aug 31, 2026 |