Search

Search Results (385329 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-51730 1 Totolink 1 T6 2026-08-31 9.1 Critical
Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51739 1 Totolink 1 T6 2026-08-31 N/A
Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-54598 1 Ellite 1 Wallos 2026-08-31 7.5 High
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has been patched in version 4.9.4.
CVE-2026-54179 1 Laravel-backpack 1 Crud 2026-08-31 4.4 Medium
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/SingleBase64Image.php methods SingleBase64Image::uploadFiles and SingleBase64Image::uploadRepeatableFiles, used by image fields through withFiles(), accept any data URI beginning with data:image without validating the declared MIME subtype or decoded bytes, while src/app/Library/Uploaders/Support/FileNameGenerator.php method FileNameGenerator::getExtensionFromFile applies mime_content_type() to the data URI instead of the decoded content. An authenticated administrator can therefore store arbitrary file content under an extensionless filename on the configured disk, which can cause stored cross-site scripting or other unintended behavior when the file is served and accessed. This issue is fixed in version 7.0.38 and 6.8.14.
CVE-2026-82330 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-08-31 6.1 Medium
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
CVE-2026-30060 1 Free5gc 1 Free5gc 2026-08-31 7.5 High
An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.
CVE-2026-82229 2 Miniorange, Wordpress 2 Wordpress Social Login And Register, Wordpress 2026-08-31 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
CVE-2026-81293 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-08-31 9.3 Critical
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
CVE-2026-82221 2 Metagauss, Wordpress 2 Registrationmagic, Wordpress 2026-08-31 7.1 High
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-82224 2 Iova.mihai, Wordpress 2 Slicewp, Wordpress 2026-08-31 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
CVE-2026-82228 2 Siteground, Wordpress 2 Siteground Security, Wordpress 2026-08-31 8.1 High
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
CVE-2026-18545 2 Ibm, Langflow 2 Langflow Oss, Langflow 2026-08-31 4.3 Medium
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2026-18729 2 Ibm, Langflow 2 Langflow Oss, Langflow 2026-08-31 8.8 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVE-2026-18891 2 Ibm, Langflow 2 Langflow Oss, Langflow 2026-08-31 8.2 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
CVE-2026-82954 1 Dokploy 1 Dokploy 2026-08-31 9.9 Critical
A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-81780 2 Hashthemes, Wordpress 2 Hash Form, Wordpress 2026-08-31 10 Critical
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-82225 2 Metagauss, Wordpress 2 Registrationmagic, Wordpress 2026-08-31 7.4 High
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-81768 2 Highwarden, Wordpress 2 Super Store Finder, Wordpress 2026-08-31 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
CVE-2026-18904 2 Ibm, Langflow 2 Langflow Oss, Langflow 2026-08-31 8.2 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
CVE-2026-19286 2 Ibm, Langflow 2 Langflow Oss, Langflow 2026-08-31 9.8 Critical
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.