| CVE-2026-82598 | 5.5 | 23.4 | n/a | SeaCMS | CWE-74 | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82624 | 5.5 | 23.4 | code-projects | Simple Inventory System | CWE-200 | code-projects Simple Inventory System Database Backup File inventorymanagemen… |
| CVE-2026-82564 | 7.1 | 23.3 | ash-project | ash_ai | CWE-639 | Identity tool filter in AshAi accepts operator maps, allowing update or destr… |
| CVE-2026-82599 | 2.1 | 23.3 | n/a | SeaCMS | CWE-22 | SeaCMS Avatar Upload member.php unlink path traversal |
| CVE-2026-82602 | 5.5 | 22.9 | n/a | SeaCMS | CWE-285 | SeaCMS ass.php authorization |
| CVE-2026-82629 | 2.0 | 22.8 | jeecgboot | jeewx-boot | CWE-284 | jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwi… |
| CVE-2024-58379 | 6.9 | 22.6 | nodemailer | nodemailer | CWE-1333 | nodemailer before 6.9.9 ReDoS via attachDataUrls parameter |
| CVE-2026-81852 | 2.1 | 22.6 | ash-project | ash_admin | CWE-330 | AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass |
| CVE-2026-82603 | 2.1 | 22.6 | n/a | SeaCMS | CWE-22 | SeaCMS Comment Cache member.php del_pl path traversal |
| CVE-2026-82619 | 2.1 | 22.4 | Systerel | S2OPC | CWE-119 | Systerel S2OPC subscription_mgr.c use after free |
| CVE-2026-82859 | 9.3 | 22.3 | kerberosmansour | hulumi | CWE-284 | hulumi before v1.3.2 SCP Template Tag-on-Create Bypass |
| CVE-2026-82860 | 9.3 | 22.3 | hulumi | policies | CWE-269 | @hulumi/policies before 1.3.2 Admin Policy Bypass |
| CVE-2026-75757 | 8.3 | 22.3 | ash-project | ash_admin | CWE-565 | AshAdmin cookie reader matches names by substring, enabling actor/session sha… |
| CVE-2026-82726 | 6.3 | 22.3 | ash-project | ash_phoenix | CWE-178 | AshPhoenix get_subdomain maps a crafted or differently-cased Host header to a… |
| CVE-2026-53620 | 5.3 | 20.9 | GROWI, Inc. | GROWI | CWE-639 | GROWI contains a vulnerability with an authorization bypass through user-cont… |
| CVE-2026-82607 | 5.5 | 20.9 | Cozmoslabs | Profile Builder Plugin | CWE-284 | Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wp… |
| CVE-2026-82856 | 9.3 | 20.5 | hulumi | policies | CWE-284 | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
| CVE-2026-82857 | 9.3 | 20.5 | kerberosmansour | hulumi | CWE-269 | hulumi before v1.3.2 Privilege Escalation via IAM Policy |
| CVE-2026-75760 | 7.1 | 20.4 | ash-project | ash_ai | CWE-209 | AshAi vectorize change leaks raw embedding-provider errors, including credent… |
| CVE-2026-77850 | 8.4 | 19.8 | ash-project | ash_admin | CWE-79 | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content |
| CVE-2026-82601 | 2.1 | 19.9 | n/a | SeaCMS | CWE-79 | SeaCMS err.php cross site scripting |
| CVE-2026-82618 | 5.3 | 19.7 | Systerel | S2OPC | CWE-119 | Systerel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matri… |
| CVE-2026-82625 | 2.1 | 19.2 | code-projects | Simple Inventory System | CWE-79 | code-projects Simple Inventory System User Registration register.php cross si… |
| CVE-2026-82615 | 5.5 | 18.6 | itsourcecode | Online Medicine Delivery System | CWE-74 | itsourcecode Online Medicine Delivery System Password Recovery passwordrecove… |
| CVE-2026-82722 | 8.3 | 18.6 | ash-project | ash_admin | CWE-770 | AshAdmin LiveView events intern atoms from client input, exhausting the atom … |
| CVE-2026-82579 | 6.0 | 18.6 | ash-project | ash_ai | CWE-835 | AshAi tool loop never terminates when all tool calls are filtered out, enabli… |
| CVE-2026-82580 | 5.3 | 18.6 | ash-project | ash_ai | CWE-209 | AshAi echoes raw tool exception messages into the conversation, disclosing in… |
| CVE-2026-82727 | 2.3 | 18.6 | ash-project | ash_phoenix | CWE-209 | AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error m… |
| CVE-2026-82681 | 2.0 | 18.6 | ash-project | ash_admin | CWE-116 | Query-parameter injection in AshAdmin row-action links via unencoded string p… |
| CVE-2026-82612 | 5.5 | 17.9 | itsourcecode | Online Medicine Delivery System | CWE-74 | itsourcecode Online Medicine Delivery System Product Detail index.php loadRes… |
| CVE-2026-82613 | 5.5 | 17.9 | itsourcecode | Online Medicine Delivery System | CWE-74 | itsourcecode Online Medicine Delivery System Product Search index.php loadRes… |
| CVE-2026-82614 | 5.5 | 17.9 | itsourcecode | Online Medicine Delivery System | CWE-74 | itsourcecode Online Medicine Delivery System Product Category Filter index.ph… |
| CVE-2026-82872 | 7.1 | 17.2 | ToolJet | ToolJet | CWE-639 | ToolJet before v3.16.208 Cross-Workspace Authorization Bypass |
| CVE-2026-81853 | 2.3 | 17.3 | ash-project | ash_admin | CWE-639 | AshAdmin composite primary key decoding accepts arbitrary fields, enabling a … |
| CVE-2026-82725 | 2.3 | 17.3 | ash-project | ash_phoenix | CWE-639 | AshPhoenix FilterForm allows filtering across non-public relationships, discl… |
| CVE-2026-82874 | 2.4 | 17.2 | ToolJet | ToolJet | CWE-639 | ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db |
| CVE-2026-82861 | 8.7 | 17.0 | hulumi | policies | CWE-284 | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass |
| CVE-2026-82659 | 7.1 | 16.7 | nodemailer | nodemailer | CWE-73 | nodemailer before 9.0.1 File Read and SSRF via raw option |
| CVE-2026-82600 | 5.5 | 16.7 | n/a | SeaCMS | CWE-74 | SeaCMS zyapi.php sql injection |
| CVE-2026-82864 | 7.1 | 16.0 | pdfme | pdf-lib | CWE-409 | pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb |
| CVE-2026-82724 | 7.6 | 15.7 | ash-project | ash_phoenix | CWE-863 | Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_… |
| CVE-2026-58301 | 5.9 | 14.4 | Apache Software Foundation | Apache Shiro | CWE-918 | Apache Shiro: Server-side POST request may be steered to an alternate host |
| CVE-2026-82838 | 6.4 | 14.1 | pretix | venueless | CWE-80 | Default webserver configuration with incorrect CSP |
| CVE-2026-82608 | 2.1 | 14.1 | n/a | Kamailio | CWE-119 | Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds |
| CVE-2026-82869 | 8.2 | 12.2 | ToolJet | ToolJet | CWE-639 | ToolJet Database before v3.16.44 Privilege Escalation via join_tables |
| CVE-2026-82871 | 8.2 | 12.2 | ToolJet | ToolJet | CWE-862 | ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes |
| CVE-2026-82870 | 7.0 | 12.1 | ToolJet | ToolJet | CWE-639 | ToolJet before v3.16.208 Cross-Tenant Database Manipulation |
| CVE-2026-82866 | 8.9 | 12.0 | pdfme | common | CWE-918 | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch |
| CVE-2026-82620 | 2.1 | 10.4 | Soarkey | StudentManagement | CWE-74 | Soarkey StudentManagement/学生信息管理系统 CourseDao.java CourseDao.course_ranking sq… |
| CVE-2026-82609 | 2.1 | 9.9 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System inv_edit.php sql injection |
| CVE-2026-82622 | 2.0 | 9.7 | code-projects | Employee Leave Managing System | CWE-79 | code-projects Employee Leave Managing System Employee Profile Update editacti… |
| CVE-2026-19410 | 9.4 | 9.5 | Google Cloud | Google Cloud Build | CWE-345 | Google Cloud Build Comment Control Bypass via Webhook Suppression |
| CVE-2026-81315 | 7.4 | 8.7 | ash-project | ash_ai | CWE-346 | MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-… |
| CVE-2026-82661 | 5.3 | 8.7 | nodemailer | nodemailer | CWE-93 | Nodemailer CRLF Injection via List-* Header Comments |
| CVE-2026-82660 | 5.3 | 8.6 | nodemailer | nodemailer | CWE-862 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess |
| CVE-2026-82858 | 9.3 | 8.5 | hulumi | drift | CWE-345 | @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
| CVE-2026-82867 | 5.3 | 7.9 | pdfme | schemas | CWE-79 | @pdfme/schemas before 5.5.9 Cross-Site Scripting via Select |
| CVE-2026-82873 | 5.3 | 7.9 | ToolJet | ToolJet | CWE-639 | ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export |
| CVE-2026-82671 | 4.6 | 5.3 | IObit | Unlocker | CWE-266 | IObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess pri… |
| CVE-2026-82868 | 5.3 | 4.9 | pdfme | schemas | CWE-79 | @pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG |
| CVE-2026-82863 | 8.7 | 4.1 | hulumi | baseline | CWE-778 | @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection |
| CVE-2026-82670 | 4.8 | 4.1 | IObit | Uninstaller | CWE-266 | IObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges ma… |
| CVE-2026-40463 | 7.6 | 3.8 | Nokia | WaveSuite | CWE-284 | An Insufficient Role-based Access Control Vulnerability in WaveSuite |
| CVE-2026-40465 | 5.3 | 3.6 | Nokia | NSP | CWE-601 | An Open Re-direct Vulnerability in Nokia NSP |
| CVE-2026-82875 | 5.1 | 3.6 | ToolJet | ToolJet | CWE-863 | ToolJet before v3.16.208 Authorization Bypass via organizationId |
| CVE-2026-40464 | 5.4 | 3.4 | Nokia | NSP | CWE-79 | A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP |
| CVE-2026-77013 | 5.3 | 3.4 | Unknown | 爱采集数据采集和发布插件 | CWE-862 | Icollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted M… |
| CVE-2026-82862 | 8.6 | 3.0 | kerberosmansour | hulumi | CWE-426 | Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files |
| CVE-2026-82865 | 2.1 | 2.6 | pdfme | schemas | CWE-79 | pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label |
| CVE-2026-82662 | 8.3 | 2.4 | nodemailer | nodemailer | CWE-295 | Nodemailer before 8.0.8 TLS Certificate Validation Bypass |
| CVE-2026-82628 | 9.3 | 1.8 | Colorful | iGameCenter | CWE-266 | Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges mana… |
| CVE-2026-82596 | 1.9 | 1.6 | n/a | LatencyUtils | CWE-119 | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause… |
| CVE-2026-81779 | 10.0 | — | Silk Themes | Newspapers X | CWE-1284 | WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability |
| CVE-2026-81780 | 10.0 | — | hashthemes | Hash Form | CWE-434 | WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability |
| CVE-2026-82970 | 10.0 | — | WP Legal Pages | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | CWE-434 | WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 … |
| CVE-2026-79748 | 9.9 | — | samanhappy | mcphub | CWE-862 | MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (miss… |
| CVE-2026-82226 | 9.8 | — | Tickera | Tickera | CWE-502 | WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability |
| CVE-2026-53552 | 9.6 | — | zhenorzz | goploy | CWE-639 | Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and … |
| CVE-2026-59111 | 9.3 | — | Ministry of the Interior (MVČR) | eObčanka-Identifikace | CWE-78 | Command Injection vulnerability in eObčanka-Identifikace |
| CVE-2026-73819 | 9.3 | — | Ebyte | Ebyte NA111-M Firmware | CWE-1390 | Ebyte NA111-M Weak Authentication |
| CVE-2026-76133 | 9.3 | — | Ebyte | Ebyte NA111-M Firmware | CWE-327 | Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm |
| CVE-2026-81293 | 9.3 | — | Passionate Programmer Peter | WP Data Access | CWE-89 | WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability |
| CVE-2026-81756 | 9.3 | — | Autorius E-goi | Smart Marketing SMS and Newsletters Forms | CWE-89 | WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL In… |
| CVE-2026-81763 | 9.3 | — | ウェブ屋のさとーさん | Throws SPAM Away | CWE-89 | WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability |
| CVE-2026-82693 | 9.3 | — | Tenda | AC1206 | CWE-287 | Tenda AC1206 Web UI telnet TendaTelnet missing authentication |
| CVE-2026-82694 | 9.3 | — | Tenda | AC1206 | CWE-287 | Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication |
| CVE-2026-82695 | 9.3 | — | Tenda | AC18 | CWE-287 | Tenda AC18 Telnet telnet missing authentication |
| CVE-2026-82876 | 9.3 | — | Phison Electronics Corporation | PS3111-S11 Controller Firmware | CWE-347 | Phison PS3111-S11 Controller Firmware Signature Verification Bypass |
| CVE-2026-82971 | 9.3 | — | QVidium | Opera11 | CWE-74 | QVidium Opera11 CGI Script net_tr.cgi command injection |
| CVE-2026-66047 | 9.2 | — | Proper Fraction | ProfilePress | CWE-306 | ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Insta… |
| CVE-2026-51679 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51680 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51681 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51720 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 … |
| CVE-2026-51725 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5… |
| CVE-2026-51730 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5… |
| CVE-2026-78078 | 8.9 | — | joomshaper.com | Helix Ultimate extension for Joomla | CWE-434 | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content… |
| CVE-2026-5956 | 8.8 | — | Ankara Hosting | Site Management Panel | CWE-89 | SQLi in Ankara Hosting's Site Management Panel |
| CVE-2026-12894 | 8.8 | — | Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | CWE-1336 | Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side te… |
| CVE-2026-78074 | 8.8 | — | miniorgange.com | miniOrange Oauth Client (free) extension for Joomla | CWE-284 | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension dein… |
| CVE-2026-79744 | 8.8 | — | samanhappy | mcphub | CWE-269 | MCPHub: Missing Authorization on `PUT /api/system-config` Lets Any Non-Admin … |
| CVE-2026-82217 | 8.8 | — | Eclipse Foundation | Eclipse Theia | CWE-22 | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agen… |
| CVE-2026-83596 | 8.8 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-120 | Webkitgtk: validate the full featurelist array once in opentypeverticaldata f… |
| CVE-2026-75133 | 8.7 | — | Fahad Mahmood | Keep Backup Daily | CWE-306 | Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via… |
| CVE-2026-77966 | 8.7 | — | Ebyte | Ebyte NA111-M Firmware | CWE-862 | Ebyte NA111-M Missing Authorization |
| CVE-2026-82880 | 8.7 | — | yacy | yacy_search_server | CWE-611 | YaCy Search Server through 1.941 XML External Entity Injection via Parsers |
| CVE-2026-82882 | 8.7 | — | devtron-labs | devtron | CWE-862 | Devtron through 2.2.0 Missing Authorization via webhook API token endpoint |
| CVE-2026-83497 | 8.7 | — | OpenSearch | OpenSearch | CWE-502 | Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination |
| CVE-2026-72001 | 8.6 | — | Pangolin | Pangolin | CWE-639 | Pangolin < 1.22.0 Authentication Bypass via Share-Link Endpoint |
| CVE-2026-78077 | 8.6 | — | joomshaper.com | Helix Ultimate extension for Joomla | CWE-79 | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in Mega… |
| CVE-2026-81889 | 8.6 | — | Studio-42 | elFinder | CWE-918 | elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents… |
| CVE-2026-82689 | 8.6 | — | D-Link | DNS-320L | CWE-77 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os comma… |
| CVE-2026-82692 | 8.6 | — | D-Link | DNS-340L | CWE-77 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection |
| CVE-2026-82954 | 8.6 | — | n/a | Dokploy | CWE-22 | Dokploy Settings application.ts writeTraefikConfigInPath path traversal |
| CVE-2026-83524 | 8.6 | — | RedPort | Optimizer wXa-203 | CWE-74 | RedPort Optimizer wXa-223 System Clock datetime.php exec command injection |
| CVE-2026-61639 | 8.5 | — | ellite | Wallos | CWE-22 | Wallos: Zip Slip path traversal in database restore writes files to webroot |
| CVE-2026-61640 | 8.5 | — | ellite | Wallos | CWE-918 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration |
| CVE-2026-81287 | 8.5 | — | Syed Balkhi | Charitable | CWE-89 | WordPress Charitable plugin <= 1.8.12.1 - SQL Injection vulnerability |
| CVE-2026-82688 | 8.5 | — | D-Link | DNS-340L | CWE-77 | D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection |
| CVE-2026-82690 | 8.5 | — | D-Link | DNS-327L | CWE-77 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection |
| CVE-2026-82691 | 8.5 | — | D-Link | DNS-320L | CWE-77 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injec… |
| CVE-2026-82807 | 8.5 | — | ieungSoft | Ultra RAMDisk Pro | CWE-266 | ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management |
| CVE-2026-82908 | 8.5 | — | MSI | Dragon Center | CWE-189 | MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow |
| CVE-2026-53507 | 8.3 | — | oasdiff | oasdiff-action | CWE-200 | oasdiff actions resolve external $refs by default, enabling SSRF and disclosu… |
| CVE-2026-54600 | 8.2 | — | ellite | Wallos | CWE-287 | Wallos: Unauthenticated database replacement via import endpoint on fresh ins… |
| CVE-2026-61638 | 8.2 | — | ellite | Wallos | CWE-918 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port |
| CVE-2026-75594 | 8.2 | — | getkirby | kirby | CWE-22 | Kirby: Access to image files and limited access to JSON files outside of the … |
| CVE-2026-77348 | 8.2 | — | ellite | Wallos | CWE-441 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still … |
| CVE-2026-61641 | 8.1 | — | ellite | Wallos | CWE-287 | Wallos: OIDC account takeover via email-based account linking without `email_… |
| CVE-2026-79746 | 8.1 | — | samanhappy | mcphub | CWE-863 | MCPHub: Server-scoped bearer key gains access to an entire group via partial … |
| CVE-2026-81891 | 8.1 | — | Studio-42 | elFinder | CWE-434 | elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file up… |
| CVE-2026-81892 | 8.1 | — | EasyCorp | EasyAdminBundle | CWE-639 | EasyAdmin custom-action dispatcher bypasses access_control on other routes |
| CVE-2026-82228 | 8.1 | — | SiteGround | SiteGround Security | CWE-290 | WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability |
| CVE-2026-13732 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via cra… |
| CVE-2026-19702 | 7.8 | — | TÜBİTAK BİLGEM Software Technologies Research Institute | Pardus Boot Repair | CWE-78 | OS Command Injection in TÜBİTAK BİLGEM's Pardus Boot Repair |
| CVE-2026-53553 | 7.7 | — | zhenorzz | goploy | CWE-22 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Rem… |
| CVE-2026-79750 | 7.7 | — | samanhappy | mcphub | CWE-639 | MCPHub authenticated horizontal IDOR: any non-admin user executes tools on ot… |
| CVE-2026-79749 | 7.6 | — | samanhappy | mcphub | CWE-918 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation |
| CVE-2026-17615 | 7.5 | — | Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | CWE-611 | Resteasy-core: resteasy sourceprovider remote unauthenticated file read |
| CVE-2026-19616 | 7.5 | — | TBC Technology Inc. | KitLogistic | CWE-862 | Information Disclosure in TBC Technology's KitLogistic |
| CVE-2026-19873 | 7.5 | — | — | HTML-FormFu | CWE-770 | HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an … |
| CVE-2026-54598 | 7.5 | — | ellite | Wallos | CWE-306 | Missing Authentication for Critical Function in wallos |
| CVE-2026-54599 | 7.5 | — | ellite | Wallos | CWE-352 | Wallos: OIDC state parameter never validated — login CSRF / account takeover |
| CVE-2026-76763 | 7.5 | — | Red Hat | Red Hat build of Quarkus | CWE-1284 | Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of ser… |
| CVE-2026-81296 | 7.5 | — | WP Manage Ninja | Fluent Forms Pro Add On Pack | CWE-862 | WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Broken Access Contr… |
| CVE-2026-81297 | 7.5 | — | WP Manage Ninja | Fluent Forms Pro Add On Pack | CWE-266 | WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Privilege Escalatio… |
| CVE-2026-82393 | 7.5 | — | pnpm | pnpm | CWE-22 | pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary… |
| CVE-2026-82397 | 7.5 | — | tornadoweb | tornado | CWE-400 | Tornado: Urlencoded body parsing omits max_num_fields, so one request can sta… |
| CVE-2026-82225 | 7.4 | — | Metagauss | RegistrationMagic | CWE-288 | WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnera… |
| CVE-2026-82680 | 7.4 | — | D-Link | DSM-G600 | CWE-119 | D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write |
| CVE-2026-78422 | 7.3 | — | z-galaxy | zbus_polkit | CWE-367 | zbus_polkit: polkit authorization bypass via PID reuse due to incorrect D-Bus… |
| CVE-2026-71415 | 7.1 | — | getkirby | kirby | CWE-862 | Kirby: File upload permissions are not checked during processing of chunk data |
| CVE-2026-75132 | 7.1 | — | Tranquil_IT | WAPT | CWE-89 | WAPT Server SQL Injection via /api/v3/hosts Endpoint |
| CVE-2026-77975 | 7.1 | — | Ebyte | Ebyte NE2-D11 Firmware | CWE-312 | Ebyte NA111-M Cleartext Storage of Sensitive Information |
| CVE-2026-79745 | 7.1 | — | samanhappy | mcphub | CWE-862 | MCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorize… |
| CVE-2026-79747 | 7.1 | — | samanhappy | mcphub | CWE-918 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary… |
| CVE-2026-81290 | 7.1 | — | Icegram | Email Subscribers & Newsletters | CWE-79 | WordPress Email Subscribers & Newsletters plugin <= 5.9.33 - Cross Site Scrip… |
| CVE-2026-81291 | 7.1 | — | Uncode | Uncode | CWE-79 | WordPress Uncode theme <= 2.12.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-81298 | 7.1 | — | varunvairavanlc | LeadConnector | CWE-79 | WordPress LeadConnector plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-81764 | 7.1 | — | Acato | Email Essentials | CWE-79 | WordPress Email Essentials plugin <= 6.0.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-81765 | 7.1 | — | Tailored Media | Tailored Tools | CWE-79 | WordPress Tailored Tools plugin <= 3.0.2 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-81768 | 7.1 | — | highwarden | Super Store Finder | CWE-79 | WordPress Super Store Finder plugin <= 7.10 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-82221 | 7.1 | — | Metagauss | RegistrationMagic | CWE-79 | WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vu… |
| CVE-2026-82224 | 7.1 | — | iova.mihai | SliceWP | CWE-79 | WordPress SliceWP plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-82229 | 7.1 | — | miniOrange | WordPress Social Login and Register | CWE-79 | WordPress WordPress Social Login and Register plugin <= 7.8.2 - Cross Site Sc… |
| CVE-2026-82392 | 7.1 | — | pnpm | pnpm | CWE-22 | pnpm: Virtual store linker path traversal via unvalidated depPath name in loc… |
| CVE-2026-82877 | 7.1 | — | ILIAS-eLearning e.V. | ILIAS | CWE-22 | ILIAS before 9.22 Arbitrary File Read via SOAP addFile |
| CVE-2026-82346 | 7.0 | — | HP Inc | HP ImageDiags | CWE-379 | HP ImageDiags - Potential Escalation of Privilege |
| CVE-2026-62993 | 6.9 | — | smarty-php | smarty | CWE-918 | Smarty: SSRF via redirect bypass of trusted_uri using {fetch} |
| CVE-2026-75592 | 6.9 | — | getkirby | kirby | CWE-22 | Kirby: Access to image files outside of the site root via path traversal in t… |
| CVE-2026-79743 | 6.9 | — | samanhappy | mcphub | CWE-22 | MCPHub: Path Traversal via Malicious MCPB Manifest Name |
| CVE-2026-82398 | 6.9 | — | py-pdf | pypdf | CWE-407 | pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace |
| CVE-2026-83492 | 6.9 | — | Extend Themes | Kubio AI Website Builder | CWE-20 | WordPress Kubio AI Website Builder - Denial Of Service |
| CVE-2026-14696 | 6.5 | — | zephyrproject | zephyr | CWE-401 | Ethernet bridge RX packet leak enables denial of service via RX buffer-pool e… |
| CVE-2026-14697 | 6.5 | — | zephyrproject | zephyr | CWE-401 | IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of se… |
| CVE-2026-81280 | 6.5 | — | UKR Solution | Print Barcode Labels for your WooCommerce products/orders | CWE-201 | WordPress Print Barcode Labels for your WooCommerce products/orders plugin <=… |
| CVE-2026-81762 | 6.5 | — | magepeopleteam | Booking and Rental Manager | CWE-862 | WordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control … |
| CVE-2026-81778 | 6.5 | — | The4 | Kalles Addons | CWE-79 | WordPress Kalles Addons plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2023-20511 | 6.4 | — | AMD | AMD Radeon™ Instinct™ MI25 Graphics Products | CWE-763 | Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow… |
| CVE-2026-14366 | 6.4 | — | zephyrproject | zephyr | CWE-416 | SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt |
| CVE-2026-81758 | 6.3 | — | OwnerRez | OwnerRez API | CWE-862 | WordPress OwnerRez API plugin <= 1.2.6 - Broken Access Control vulnerability |
| CVE-2026-76986 | 6.1 | — | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue |
| CVE-2026-53508 | 6.0 | — | oasdiff | oasdiff | CWE-73 | oasdiff does not enforce --allow-external-refs=false on the git-revision load… |
| CVE-2026-82698 | 5.5 | — | sambitraj | Student-Management-System | CWE-1393 | sambitraj Student-Management-System aca.sql default password |
| CVE-2026-82701 | 5.5 | — | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System Search Functionality action.php sql inje… |
| CVE-2026-82797 | 5.5 | — | Samsung Open Source | rlottie | CWE-674 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Se… |
| CVE-2026-82801 | 5.5 | — | NASA | earthdata-search | CWE-918 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side reques… |
| CVE-2026-82802 | 5.5 | — | NASA | earthdata-search | CWE-918 | NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLam… |
| CVE-2026-82803 | 5.5 | — | armink | struct2json | CWE-404 | armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMEN… |
| CVE-2026-82808 | 5.5 | — | Inbox Foundry | ActiveInbox Extension | CWE-259 | Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker… |
| CVE-2026-82815 | 5.5 | — | MegaEase | EaseProbe | CWE-266 | MegaEase EaseProbe Middleware server.go realIP access control |
| CVE-2026-82914 | 5.5 | — | kishan0725 | Hospital-Management-System | CWE-74 | kishan0725 Hospital-Management-System search.php sql injection |
| CVE-2026-82919 | 5.5 | — | cu | silicon | CWE-287 | cu silicon edit Endpoint views.py create_app missing authentication |
| CVE-2026-82921 | 5.5 | — | ShopEx | ECShop | CWE-284 | ShopEx ECShop pack.php check_img_type unrestricted upload |
| CVE-2026-82922 | 5.5 | — | ShopEx | ECShop | CWE-74 | ShopEx ECShop flow.php flow_update_cart sql injection |
| CVE-2026-82957 | 5.5 | — | hyperledger-firefly | firefly | CWE-918 | hyperledger-firefly Webhook Subscription webhooks.go ValidateOptions server-s… |
| CVE-2026-14368 | 5.4 | — | zephyrproject | zephyr | CWE-193 | Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser |
| CVE-2026-81267 | 5.4 | — | Mozilla | Firefox for iOS | CWE-451 | Stalled popup navigation could allow address bar origin spoofing in Firefox f… |
| CVE-2026-81278 | 5.4 | — | WPExperts | Post SMTP | CWE-862 | WordPress Post SMTP plugin 4.0.0-beta.1 - Settings Change vulnerability |
| CVE-2026-81888 | 5.4 | — | honojs | @hono/oauth-providers | CWE-352 | @hono/oauth-providers: OAuth state check fails open on omitted state, enablin… |
| CVE-2026-81890 | 5.4 | — | Studio-42 | elFinder | CWE-352 | elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP conne… |
| CVE-2026-82396 | 5.4 | — | sulu | sulu | CWE-79 | Sulu: Stored XSS via media download inline-disposition override |
| CVE-2026-82852 | 5.4 | — | MapSVG | MapSVG | CWE-918 | WordPress MapSVG plugin <= 8.15.0 - Server Side Request Forgery (SSRF) vulner… |
| CVE-2026-70449 | 5.3 | — | Apache Software Foundation | Apache Wicket | CWE-22 | Apache Wicket: Path traversal in resource style/variation/locale |
| CVE-2026-74010 | 5.3 | — | John James Jacoby | bbPress | CWE-862 | WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerability |
| CVE-2026-78079 | 5.3 | — | joomshaper.com | Helix Ultimate extension for Joomla | CWE-601 | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content… |
| CVE-2026-82394 | 5.3 | — | sulu | sulu | CWE-862 | Sulu: Fix authorization bypass when creating preview links |
| CVE-2026-82395 | 5.3 | — | sulu | sulu | CWE-639 | Sulu: Media move/update authorization bypass (IDOR) |
| CVE-2026-82878 | 5.3 | — | dataease | dataease | CWE-862 | DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Lin… |
| CVE-2026-82879 | 5.3 | — | dataease | dataease | CWE-863 | DataEase before 2.10.26 Access Control Bypass via Share Tickets |
| CVE-2026-75802 | 5.1 | — | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRendere… |
| CVE-2026-76982 | 5.1 | — | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: XSS in Button via its model object |
| CVE-2026-76983 | 5.1 | — | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel |
| CVE-2026-76984 | 5.1 | — | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute |
| CVE-2026-76985 | 5.1 | — | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: XSS in Palette via getAdditionalAttributes |
| CVE-2026-78075 | 5.1 | — | joomshaper.com | Helix Ultimate extension for Joomla | CWE-639 | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog… |
| CVE-2026-78076 | 5.1 | — | joomshaper.com | Helix Ultimate extension for Joomla | CWE-284 | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authoriza… |
| CVE-2026-81887 | 5.1 | — | livewire | livewire | CWE-79 | Livewire DOM-based cross-site scripting during client-side state handling |
| CVE-2026-82881 | 5.1 | — | apconw | Aix-DB | CWE-79 | Aix-DB through 1.2.4 Stored Cross-Site Scripting via Markdown |
| CVE-2026-71378 | 4.6 | — | Apache Software Foundation | Apache Wicket | CWE-352 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in Resourc… |
| CVE-2026-77353 | 4.6 | — | ellite | Wallos | CWE-74 | Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export |
| CVE-2026-54179 | 4.4 | — | Laravel-Backpack | CRUD | CWE-79 | backpack/crud: SingleBase64Image accepts any base64 payload behind a `data:im… |
| CVE-2026-50198 | 4.3 | — | ellite | Wallos | CWE-639 | Wallos: Cross-user subscription cost inference via replacement_subscription_id |
| CVE-2026-50199 | 4.3 | — | ellite | Wallos | CWE-863 | Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate re… |
| CVE-2026-52730 | 4.3 | — | xibosignage | xibo-cms | CWE-862 | Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator pr… |
| CVE-2026-77352 | 4.3 | — | ellite | Wallos | CWE-918 | Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege… |
| CVE-2026-77351 | 3.5 | — | ellite | Wallos | CWE-918 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings |
| CVE-2023-31308 | 3.3 | — | AMD | AMD Radeon™ PRO V620 Graphics Products | CWE-129 | A malicious virtual function can invoke the certain command handlers in the S… |
| CVE-2026-14367 | 3.1 | — | zephyrproject | zephyr | CWE-362 | I3C IBI work-node free-list data race between ISR and workqueue thread |
| CVE-2026-21827 | 3.1 | — | HCLSoftware | Connections | CWE-359 | HCL Connections is vulnerable to an information disclosure vulnerability |
| CVE-2026-82697 | 2.9 | — | sambitraj | Student-Management-System | CWE-732 | sambitraj Student-Management-System session_start cookie httponly flag |
| CVE-2026-82906 | 2.9 | — | sdcb | chats | CWE-287 | sdcb chats Signed File Download Endpoint FileController.cs DownloadPublic mis… |
| CVE-2026-82679 | 2.1 | — | diem-project | diem | CWE-284 | diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted… |
| CVE-2026-82696 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System inv_searchfrm.php sql injection |
| CVE-2026-82700 | 2.1 | — | code-projects | Online Shopping System | CWE-79 | code-projects Online Shopping System Newsletter Subscription offersmail.php c… |
| CVE-2026-82805 | 2.1 | — | n/a | Typora | CWE-79 | Typora Mermaid Rendering cross site scripting |
| CVE-2026-82809 | 2.1 | — | vidIQ | Vision for YouTube Extension | CWE-200 | vidIQ Vision for YouTube Extension postMessage window.addEventListener inform… |
| CVE-2026-82811 | 2.1 | — | Toggl OÜ | Toggl Track Extension | CWE-345 | Toggl OÜ Toggl Track Extension postMessage origin validation |
| CVE-2026-82813 | 2.1 | — | BEN Group | TubeBuddy for YouTube Extension | CWE-345 | BEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetTok… |
| CVE-2026-82816 | 2.1 | — | dibo-software | diboot | CWE-285 | dibo-software diboot AI Session Endpoint ai-session authorization |
| CVE-2026-82817 | 2.1 | — | dibo-software | diboot | CWE-266 | dibo-software diboot Tenant Administrator Management API admin access control |
| CVE-2026-82818 | 2.1 | — | dibo-software | diboot | CWE-266 | dibo-software diboot Tenant Resource Assignment resource access control |
| CVE-2026-82820 | 2.1 | — | n/a | FLVMeta | CWE-119 | FLVMeta AMF String Processing amf.c amf_string_new heap-based overflow |
| CVE-2026-82821 | 2.1 | — | n/a | FLVMeta | CWE-404 | FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference |
| CVE-2026-82833 | 2.1 | — | Doccano | Open Source Annotation Tools for Machine Learning Practitioners | CWE-266 | Doccano Open Source Annotation Tools for Machine Learning Practitioners Proje… |
| CVE-2026-82834 | 2.1 | — | Doccano | Open Source Annotation Tools for Machine Learning Practitioners | CWE-266 | Doccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-… |
| CVE-2026-82835 | 2.1 | — | caoqianming | django-vue-admin | CWE-266 | caoqianming django-vue-admin file access control |
| CVE-2026-82905 | 2.1 | — | sdcb | chats | CWE-918 | sdcb chats fetch-tools Endpoint McpController.cs McpController server-side re… |
| CVE-2026-82909 | 2.1 | — | QuantumNous | new-api | CWE-613 | QuantumNous new-api Revoked API Token token session expiration |
| CVE-2026-82678 | 2.0 | — | diem-project | diem | CWE-77 | diem-project diem Administrative Console actions.class.php executeCommand os … |
| CVE-2026-82699 | 2.0 | — | sambitraj | Student Management System | CWE-310 | sambitraj Student Management System Password aca.sql cleartext storage |
| CVE-2026-82702 | 2.0 | — | Edimax | BR-6214K | CWE-77 | Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection |
| CVE-2026-82703 | 2.0 | — | Edimax | BR-6214K | CWE-77 | Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection |
| CVE-2026-82677 | 1.9 | — | valkey-io | valkey | CWE-119 | valkey-io valkey Module Timer module.c moduleTimerHandler double free |
| CVE-2026-82810 | 1.9 | — | extension.vn | 2FA Authenticator Extension | CWE-200 | extension.vn 2FA Authenticator Extension Background Service Worker chrome.run… |
| CVE-2025-63607 | await | — | n/a | n/a | — | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display… |
| CVE-2026-19953 | await | — | — | URI | CWE-1289 | URI versions before 5.36 for Perl encode non-NFC host names to non-standard p… |
| CVE-2026-38577 | await | — | n/a | n/a | — | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-2603… |
| CVE-2026-51152 | await | — | n/a | n/a | — | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 t… |
| CVE-2026-51153 | await | — | n/a | n/a | — | Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/ta… |
| CVE-2026-51666 | await | — | n/a | n/a | — | Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51667 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1… |
| CVE-2026-51668 | await | — | n/a | n/a | — | Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51669 | await | — | n/a | n/a | — | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51670 | await | — | n/a | n/a | — | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51671 | await | — | n/a | n/a | — | Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T… |
| CVE-2026-51672 | await | — | n/a | n/a | — | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51673 | await | — | n/a | n/a | — | Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51674 | await | — | n/a | n/a | — | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51675 | await | — | n/a | n/a | — | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.7… |
| CVE-2026-51676 | await | — | n/a | n/a | — | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.… |
| CVE-2026-51677 | await | — | n/a | n/a | — | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51678 | await | — | n/a | n/a | — | Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51683 | await | — | n/a | n/a | — | Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51684 | await | — | n/a | n/a | — | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51686 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51687 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.… |
| CVE-2026-51688 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.… |
| CVE-2026-51689 | await | — | n/a | n/a | — | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51690 | await | — | n/a | n/a | — | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51691 | await | — | n/a | n/a | — | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.… |
| CVE-2026-51692 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51693 | await | — | n/a | n/a | — | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51694 | await | — | n/a | n/a | — | Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.… |
| CVE-2026-51695 | await | — | n/a | n/a | — | Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51696 | await | — | n/a | n/a | — | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4… |
| CVE-2026-51697 | await | — | n/a | n/a | — | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51698 | await | — | n/a | n/a | — | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1… |
| CVE-2026-51699 | await | — | n/a | n/a | — | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51700 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.… |
| CVE-2026-51701 | await | — | n/a | n/a | — | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1… |
| CVE-2026-51702 | await | — | n/a | n/a | — | Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 … |
| CVE-2026-51703 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.… |
| CVE-2026-51704 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1… |
| CVE-2026-51705 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5… |
| CVE-2026-51706 | await | — | n/a | n/a | — | Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51708 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51709 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51710 | await | — | n/a | n/a | — | Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.… |
| CVE-2026-51711 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5… |
| CVE-2026-51712 | await | — | n/a | n/a | — | Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51713 | await | — | n/a | n/a | — | Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.… |
| CVE-2026-51714 | await | — | n/a | n/a | — | Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51715 | await | — | n/a | n/a | — | Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1… |
| CVE-2026-51716 | await | — | n/a | n/a | — | Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4… |
| CVE-2026-51717 | await | — | n/a | n/a | — | Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51718 | await | — | n/a | n/a | — | Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.… |
| CVE-2026-51719 | await | — | n/a | n/a | — | Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1… |
| CVE-2026-51721 | await | — | n/a | n/a | — | Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51722 | await | — | n/a | n/a | — | Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.… |
| CVE-2026-51723 | await | — | n/a | n/a | — | Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.… |
| CVE-2026-51724 | await | — | n/a | n/a | — | Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51726 | await | — | n/a | n/a | — | Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.… |
| CVE-2026-51727 | await | — | n/a | n/a | — | Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51728 | await | — | n/a | n/a | — | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.… |
| CVE-2026-51729 | await | — | n/a | n/a | — | Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51731 | await | — | n/a | n/a | — | Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51732 | await | — | n/a | n/a | — | Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.… |
| CVE-2026-51733 | await | — | n/a | n/a | — | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5… |
| CVE-2026-51734 | await | — | n/a | n/a | — | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1… |
| CVE-2026-51735 | await | — | n/a | n/a | — | Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51736 | await | — | n/a | n/a | — | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.7… |
| CVE-2026-51737 | await | — | n/a | n/a | — | Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.… |
| CVE-2026-51738 | await | — | n/a | n/a | — | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5… |
| CVE-2026-51739 | await | — | n/a | n/a | — | Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 … |
| CVE-2026-51740 | await | — | n/a | n/a | — | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.7… |
| CVE-2026-71257 | await | — | Apache Software Foundation | Apache Wicket | CWE-770 | Apache Wicket: Configured file upload limits are not enforced when the multip… |
| CVE-2026-75458 | await | — | n/a | n/a | — | The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open… |
| CVE-2026-75460 | await | — | n/a | n/a | — | XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerab… |
| CVE-2026-79407 | await | — | n/a | n/a | — | A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows a… |
| CVE-2026-79408 | await | — | n/a | n/a | — | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to … |
| CVE-2026-79483 | await | — | n/a | n/a | — | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL inj… |