VYPR

CVEs

378,628 total · page 222 of 7,573

  • CVE-2026-82699LowAug 31, 2026
    risk 0.18cvss 2.7epss 0.00

    A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component Password Handler. Executing a manipulation of the argument Password can lead to cleartext storage of…

  • CVE-2026-82698MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible.…

  • CVE-2026-82697LowAug 31, 2026
    risk 0.24cvss 3.7epss 0.00

    A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without 'httponly' flag. The attack may be launched remotely. A…

  • CVE-2026-82217HigAug 31, 2026
    risk 0.50cvss 8.8epss 0.00

    In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path…

  • CVE-2026-78079MedAug 31, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.

  • CVE-2026-78078HigAug 31, 2026
    risk 0.58cvss —epss 0.00

    Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict…

  • CVE-2026-78077HigAug 31, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual…

  • CVE-2026-78076MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or…

  • CVE-2026-78075MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image…

  • CVE-2026-78074HigAug 31, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are…

  • CVE-2026-76986MedAug 31, 2026
    risk 0.40cvss 6.1epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — into the…

  • CVE-2026-76985MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the…

  • CVE-2026-76763HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can…

  • CVE-2026-51681CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51680CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51679CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51678MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51677CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51676CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51675CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51674CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51673HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51672CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51671HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51670CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51669CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51668HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-19702HigAug 31, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.

  • CVE-2026-19616HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.

  • CVE-2026-75762impAug 31, 2026
    risk 0.44cvss 6.8epss —

    multicluster-global-hub: multicluster-global-hub: Transport-layer MITM: TLS CA bundle pulled from unvalidated ConfigMap, `InsecureSkipVerify` fallback

  • CVE-2026-77849impAug 31, 2026
    risk 0.64cvss 9.8epss —

    grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in `pkg/specsyncer`

  • CVE-2026-80220impAug 31, 2026
    risk 0.35cvss 5.4epss —

    postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener

  • CVE-2026-80221impAug 31, 2026
    risk 0.29cvss 4.4epss —

    grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable

  • CVE-2026-82696MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-82695CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to…

  • CVE-2026-82694CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2026-82693CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The…

  • CVE-2026-82692CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate…

  • CVE-2026-74010MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.

  • CVE-2026-5956HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.

  • CVE-2026-51667MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51666MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-12894HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive…

  • CVE-2026-82797MedAug 31, 2026
    risk 0.29cvss 5.5epss 0.00

    Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

  • CVE-2026-82691CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command…

  • CVE-2026-82690CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.02

    A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out…

  • CVE-2026-82689CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command…

  • CVE-2026-76984MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates and header tags. It escaped the attribute names it wrote, but ran the attribute values through a replacement of " with \". A…

  • CVE-2026-76983MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every WebApplication. The resolver writes the label it finds into the…

  • CVE-2026-76982MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it writes is not encoded twice — ComponentTag already encodes attribute…