Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM
CVE-2026-54179 — backpack/crud: SingleBase64Image accepts any base64 payload behind a `data:image` prefix …

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.…

backpack\\crud | Remote | Cross-Site Scripting
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-50199 — Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of lo…

wallos | Remote | Authentication
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-50198 — Wallos: Cross-user subscription cost inference via replacement_subscription_id

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a …

wallos | Remote | Information Disclosure
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-38577 — Tenda HG21 Hardcoded Credentials Vulnerability

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

Remote | Authentication
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
6.1 MEDIUM
CVE-2025-63607 — TechStore Cross-Site Scripting

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaS…

Remote | Cross-Site Scripting
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-82905 — sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery

A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. …

chats | Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.5 MEDIUM
CVE-2026-82835 — caoqianming django-vue-admin file access control

A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improp…

django-vue-admin | Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
5.5 MEDIUM
CVE-2026-82834 — Doccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-Delete Endpo…

A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This…

Aug 31, 2026 Sep 02, 2026
Aug 31, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-82833 — Doccano Open Source Annotation Tools for Machine Learning Practitioners Project Example D…

A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected …

Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
5.4 MEDIUM
CVE-2026-81267 — Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This …

firefox firefox_mobile | Remote | Denial of Service
Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-52730 — Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view …

xibo | Remote | Authorization
Aug 31, 2026 Sep 09, 2026
Aug 31, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-51740 — TOTOLINK T6 Unauthorized Process Termination

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bi…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-51739 — TOTOLINK T6 Access Control Bypass Vulnerability

Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request t…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51738 — TOTOLINK T6 Incorrect Access Control Vulnerability

Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a cr…

Remote | Authentication
Aug 31, 2026 Sep 02, 2026
Aug 31, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-51737 — TOTOLINK T6 Improper Access Control

Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-b…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.1 CRITICAL
CVE-2026-51736 — TOTOLINK T6 Improper Access Control

Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-51735 — TOTOLINK T6 Incorrect Access Control

Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51734 — TOTOLINK T6 Access Control Bypass

Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST r…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51733 — TOTOLINK T6 Access Control Bypass Vulnerability

Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /…

Remote | Authorization
Aug 31, 2026 Sep 02, 2026
Aug 31, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-51732 — TOTOLINK Access Control Bypass

Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request t…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
Showing 20 of 14957 Results