CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82694
10.0 CRITICAL

A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation …

Aug 31, 2026
CVE-2026-82693
10.0 CRITICAL

A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a …

Aug 31, 2026
CVE-2026-82692
9.9 CRITICAL

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of …

Aug 31, 2026
CVE-2026-74010
5.3 MEDIUM

Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.

Aug 31, 2026
CVE-2026-5956
8.8 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects …

Aug 31, 2026
CVE-2026-51667
4.3 MEDIUM

Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST …

Aug 31, 2026
CVE-2026-51666
4.3 MEDIUM

Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a …

Aug 31, 2026
CVE-2026-12894
8.8 HIGH

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue …

Aug 31, 2026
CVE-2026-82797
5.5 MEDIUM

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

Aug 31, 2026
CVE-2026-82691
9.1 CRITICAL

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the …

Aug 31, 2026
CVE-2026-82690
9.1 CRITICAL

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. …

Aug 31, 2026
CVE-2026-82689
9.9 CRITICAL

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the …

Aug 31, 2026
CVE-2026-76984
5.4 MEDIUM

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names it wrote, …

Aug 31, 2026
CVE-2026-76983
5.4 MEDIUM

Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every …

Aug 31, 2026
CVE-2026-76982
5.4 MEDIUM

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it …

Aug 31, 2026
CVE-2026-75802
5.4 MEDIUM

AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML …

Aug 31, 2026
CVE-2026-71378
4.6 MEDIUM

ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default …

Aug 31, 2026
CVE-2026-71257
7.5 HIGH

Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request …

Aug 31, 2026
CVE-2026-70449
5.3 MEDIUM

Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF …

Aug 31, 2026
CVE-2026-82881
5.4 MEDIUM

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and …

Aug 31, 2026
CVE-2026-82880
7.5 HIGH

YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. …

Aug 31, 2026
CVE-2026-82879
6.3 MEDIUM

DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid …

Aug 31, 2026
CVE-2026-82878
6.3 MEDIUM

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging …

Aug 31, 2026
CVE-2026-82877
6.5 MEDIUM

ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated …

Aug 31, 2026
CVE-2026-82876
8.2 HIGH

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can …

Aug 31, 2026
CVE-2026-82688
9.1 CRITICAL

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual …

Aug 31, 2026
CVE-2026-82680
8.8 HIGH

A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a …

Aug 31, 2026
CVE-2026-82679
6.3 MEDIUM

A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the …

Aug 31, 2026
CVE-2026-82678
4.7 MEDIUM

A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component Administrative …

Aug 31, 2026
CVE-2026-82677
2.4 LOW

A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation …

Aug 31, 2026
CVE-2026-82671
3.4 LOW

A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The …

Aug 31, 2026
CVE-2026-82670
4.4 MEDIUM

A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a …

Aug 31, 2026
CVE-2026-82669
5.3 MEDIUM

A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php of the component XML Parsing. …

Aug 31, 2026
CVE-2026-49003
9.6 CRITICAL

Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain …

Aug 31, 2026
CVE-2026-19873
7.5 HIGH

HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element …

Aug 31, 2026
CVE-2026-82875
5.5 MEDIUM

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's …

Aug 31, 2026
CVE-2026-82874
9.9 CRITICAL

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder …

Aug 31, 2026
CVE-2026-82873
5.0 MEDIUM

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and …

Aug 31, 2026
CVE-2026-82872
9.1 CRITICAL

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can …

Aug 31, 2026
CVE-2026-82871
7.7 HIGH

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. …

Aug 31, 2026
CVE-2026-82870
9.6 CRITICAL

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in …

Aug 31, 2026
CVE-2026-82869
7.7 HIGH

ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or …

Aug 31, 2026
CVE-2026-82868
6.1 MEDIUM

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can …

Aug 31, 2026
CVE-2026-82867
6.1 MEDIUM

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via …

Aug 31, 2026
CVE-2026-82866
6.8 MEDIUM

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who …

Aug 31, 2026
CVE-2026-82865
4.4 MEDIUM

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control …

Aug 31, 2026
CVE-2026-82864
6.5 MEDIUM

pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying …

Aug 31, 2026
CVE-2026-82863
3.3 LOW

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without …

Aug 31, 2026
CVE-2026-82862
8.4 HIGH

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place …

Aug 31, 2026
CVE-2026-82861
7.5 HIGH

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.