Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-72817 — go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72816 — go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72815 — go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remo…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.3 MEDIUM
CVE-2026-72814 — actix-web before 0.6.10 Information Disclosure via Files

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount pa…

actix-web | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72813 — actix-files before 0.6.10 Denial of Service via empty Range header

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the pr…

actix-web | Remote | Denial of Service
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-72812 — SiYuan before v3.7.4 Missing Authorization via refreshBacklink

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers …

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
10.0 CRITICAL
CVE-2026-72811 — SiYuan before v3.7.4 SQL Injection via backlink search

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor t…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.2 CRITICAL
CVE-2026-72810 — SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebS…

Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19822 — Tenda W20E QoS Edit editQos lstAdd stack-based overflow

A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the ar…

w20e | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.1 MEDIUM
CVE-2025-71405 — go-chi chi before v5.2.2 Open Redirect via RedirectSlashes

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host he…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19821 — Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer o…

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web mana…

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19815 — TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow

A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executin…

a800r_firmware a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19814 — TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow

A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of t…

a800r_firmware a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19813 — TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such ma…

a800r_firmware a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19812 — TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation o…

a800r_firmware a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.2 HIGH
CVE-2026-19794 — WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it pos…

wp-stats | Remote | Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19811 — TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The man…

a800r_firmware a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.7 MEDIUM
CVE-2026-19617 — Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-18039 — Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom …

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers t…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-16810 — Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Paramet…

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in …

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10650 Results