Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-19792 — Tenda G0 httpd web management interface module setPortMapping buffer overflow

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipu…

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19791 — Tenda G0 httpd web management interface module addStaticRoute stack-based overflow

A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a …

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.3 MEDIUM
CVE-2025-10308 — Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset

The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion …

Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19790 — Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow

A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulat…

Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19789 — Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based …

A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web manageme…

ac1206 | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19788 — Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based …

A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The m…

ac1206 | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-19787 — SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection

A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the ar…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-19786 — francoisjacquet RosarioSIS Modules.php cross-site request forgery

A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery…

Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-19785 — francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection

A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medic…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.3 MEDIUM
CVE-2026-19784 — francoisjacquet RosarioSIS Referrals.php DBUpdate authorization

A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. The attack may …

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.2 HIGH
CVE-2026-18109 — W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author…

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and ou…

w3_total_cache | Remote | Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.3 HIGH
CVE-2026-19771 — Baicells EG3661M LuCI Web luci os command injection

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argum…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-19770 — feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forg…

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download E…

| Server-Side Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-19767 — itsourcecode Hospital Management System viewdoctortimings.php sql injection

A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument d…

hospital_management_system | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-19765 — eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side requ…

A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the function loadSource of the file src/utils/swagger-parser.…

Remote | Server-Side Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19764 — Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection

A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.1 MEDIUM
CVE-2026-19763 — DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path trav…

A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This mani…

taier | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19762 — DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal

A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation …

taier | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-19761 — DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename p…

A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. The manipulatio…

taier | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19758 — dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a m…

lamp-cloud | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10663 Results