Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-19829 — 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal

A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download Endpoint. Th…

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-19828 — 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal

A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of the ar…

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.5 MEDIUM
CVE-2026-19827 — alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path tr…

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This …

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.1 HIGH
CVE-2026-19768 — Devolutions PowerShell Universal Code Injection Vulnerability

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permis…

powershell_universal | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-73673 — Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmwar…

Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authe…

| Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.6 HIGH
CVE-2026-19870 — IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation

Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and…

prospero_flow_crm | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19826 — alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject de…

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Liste…

Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19825 — SourceCodester Simple Client Management System Master.php save_service sql injection

A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manip…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19824 — Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow

A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the…

w20e | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19823 — Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow

A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a …

w20e | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-73630 — SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The en…

Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.3 MEDIUM
CVE-2026-73051 — actix-http before 3.12.1 HTTP Request Smuggling via CL.TE

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthe…

actix-web | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-73049 — SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when fil…

Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-73048 — SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access …

Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.7 HIGH
CVE-2026-72859 — Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests …

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-72838 — FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can …

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-72837 — File Browser before 2.63.20 Privilege Escalation via Proxy Authentication

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can re…

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.1 HIGH
CVE-2026-72836 — FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser…

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.8 MEDIUM
CVE-2026-72835 — filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash…

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.3 MEDIUM
CVE-2026-72834 — filebrowser before 2.63.19 Permission Bypass via checksum

filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it…

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10643 Results