Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-82797 — Samsung rlottie Uncontrolled Recursion Vulnerability

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

| Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.1 CRITICAL
CVE-2026-82691 — D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the compo…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.1 CRITICAL
CVE-2026-82690 — D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_d…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.9 CRITICAL
CVE-2026-82689 — D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handle…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.1 MEDIUM
CVE-2026-76984 — Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names…

wicket | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.1 MEDIUM
CVE-2026-76983 — Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel

Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by d…

wicket | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.1 MEDIUM
CVE-2026-76982 — Apache Wicket: XSS in Button via its model object

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value att…

wicket | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.1 MEDIUM
CVE-2026-75802 — Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaul…

AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML …

wicket | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-71378 — Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRe…

ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its d…

wicket | Cross-Site Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-71257 — Apache Wicket: Configured file upload limits are not enforced when the multipart request …

Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by anothe…

wicket | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-70449 — Apache Wicket: Path traversal in resource style/variation/locale

Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF that the servlet contai…

wicket | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-82693 — Tenda AC1206 Web UI telnet TendaTelnet missing authentication

A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead t…

ac1206 | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.8 HIGH
CVE-2026-12894 — Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side template injec…

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values …

build_of_quarkus | Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2026-74010 — WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerability

Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-82692 — D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/pass…

| Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-82881 — Aix-DB through 1.2.4 Stored Cross-Site Scripting via Markdown

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.7 HIGH
CVE-2026-82880 — YaCy Search Server through 1.941 XML External Entity Injection via Parsers

YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publis…

Remote | XML External Entity
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.3 MEDIUM
CVE-2026-82879 — DataEase before 2.10.26 Access Control Bypass via Share Tickets

DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused again…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.3 MEDIUM
CVE-2026-82878 — DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Cha…

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82877 — ILIAS before 9.22 Arbitrary File Read via SOAP addFile

ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by su…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 11986 Results