Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-19813 — TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such ma…

a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19812 — TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation o…

a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.2 HIGH
CVE-2026-19794 — WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it pos…

wp-stats | Remote | Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19811 — TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The man…

a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.7 MEDIUM
CVE-2026-19617 — Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-18039 — Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom …

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers t…

| Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-16810 — Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Paramet…

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in …

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-16739 — Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually …

| Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-15205 — Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel …

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, an…

| Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-14290 — Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode At…

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or abo…

| Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-12949 — Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register()…

Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.9 MEDIUM
CVE-2026-12743 — affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' P…

The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and includin…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19792 — Tenda G0 httpd web management interface module setPortMapping buffer overflow

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipu…

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19791 — Tenda G0 httpd web management interface module addStaticRoute stack-based overflow

A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a …

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.3 MEDIUM
CVE-2025-10308 — Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset

The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion …

Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19790 — Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow

A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulat…

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19789 — Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based …

A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web manageme…

ac1206 | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19788 — Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based …

A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The m…

ac1206 | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-19787 — SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection

A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the ar…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-19786 — francoisjacquet RosarioSIS Modules.php cross-site request forgery

A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery…

Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10666 Results