| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82221 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | ||
| CVE-2026-81892 | Hig | 0.46 | 8.1 | 0.00 | Aug 31, 2026 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed… | ||
| CVE-2026-81891 | Hig | 0.46 | 8.1 | 0.01 | Aug 31, 2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar,… | ||
| CVE-2026-81890 | Med | 0.28 | 5.4 | 0.00 | Aug 31, 2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing… | ||
| CVE-2026-81889 | Hig | 0.49 | 8.6 | 0.01 | Aug 31, 2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates… | ||
| CVE-2026-81888 | Med | 0.28 | 5.4 | 0.00 | Aug 31, 2026 | @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine… | ||
| CVE-2026-81887 | Med | 0.26 | — | 0.01 | Aug 31, 2026 | Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path… | ||
| CVE-2026-81780 | Cri | 0.65 | 10.0 | 0.01 | Aug 31, 2026 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | ||
| CVE-2026-81779 | Cri | 0.65 | 10.0 | 0.01 | Aug 31, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | ||
| CVE-2026-81778 | Med | 0.42 | 6.5 | 0.00 | Aug 31, 2026 | Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions. | ||
| CVE-2026-81768 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | ||
| CVE-2026-81765 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | ||
| CVE-2026-81764 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | ||
| CVE-2026-81763 | Cri | 0.60 | 9.3 | 0.00 | Aug 31, 2026 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | ||
| CVE-2026-81762 | Med | 0.42 | 6.5 | 0.00 | Aug 31, 2026 | Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | ||
| CVE-2026-81758 | Med | 0.41 | 6.3 | 0.00 | Aug 31, 2026 | Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | ||
| CVE-2026-81756 | Cri | 0.60 | 9.3 | 0.00 | Aug 31, 2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | ||
| CVE-2026-81298 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | ||
| CVE-2026-81297 | Hig | 0.49 | 7.5 | 0.00 | Aug 31, 2026 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | ||
| CVE-2026-81296 | Hig | 0.49 | 7.5 | 0.00 | Aug 31, 2026 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | ||
| CVE-2026-81293 | Cri | 0.60 | 9.3 | 0.00 | Aug 31, 2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | ||
| CVE-2026-81291 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | ||
| CVE-2026-81290 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2026 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | ||
| CVE-2026-81287 | Hig | 0.55 | 8.5 | 0.00 | Aug 31, 2026 | Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. | ||
| CVE-2026-81280 | Med | 0.42 | 6.5 | 0.00 | Aug 31, 2026 | Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | ||
| CVE-2026-81278 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1. | ||
| CVE-2026-79483 | Med | 0.27 | 5.3 | 0.00 | Aug 31, 2026 | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in… | ||
| CVE-2026-79408 | Cri | 0.64 | 9.8 | 0.02 | Aug 31, 2026 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. | ||
| CVE-2026-79407 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2026 | A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME… | ||
| CVE-2026-75594 | Hig | 0.46 | — | 0.01 | Aug 31, 2026 | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's… | ||
| CVE-2026-75592 | Med | 0.38 | — | 0.01 | Aug 31, 2026 | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Kirby\Filesystem\Dir::realpath() and… | ||
| CVE-2026-75460 | Med | 0.42 | 6.5 | 0.00 | Aug 31, 2026 | XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester. | ||
| CVE-2026-75458 | Hig | 0.53 | 8.1 | 0.00 | Aug 31, 2026 | The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence,… | ||
| CVE-2026-71415 | Hig | 0.39 | — | 0.00 | Aug 31, 2026 | Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Api\Upload::processChunk() persisted chunk… | ||
| CVE-2026-62993 | Med | 0.38 | — | 0.01 | Aug 31, 2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used… | ||
| CVE-2026-61641 | Hig | 0.46 | 8.1 | 0.01 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email… | ||
| CVE-2026-61640 | Hig | 0.48 | — | 0.01 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs… | ||
| CVE-2026-61639 | Hig | 0.48 | — | 0.01 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to… | ||
| CVE-2026-61638 | Hig | 0.46 | — | 0.01 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port.… | ||
| CVE-2026-54600 | Hig | 0.46 | — | 0.01 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire… | ||
| CVE-2026-54599 | Hig | 0.42 | — | 0.00 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session… | ||
| CVE-2026-54598 | Hig | 0.42 | 7.5 | 0.00 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against… | ||
| CVE-2026-54179 | Med | 0.22 | 4.4 | 0.00 | Aug 31, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/SingleBase64Image.php methods… | ||
| CVE-2026-50199 | Med | 0.21 | 4.3 | 0.00 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal… | ||
| CVE-2026-50198 | Med | 0.21 | 4.3 | 0.00 | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID belonging to another user. The write is accepted, and later the… | ||
| CVE-2026-38577 | Cri | 0.64 | 9.8 | 0.00 | Aug 31, 2026 | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | ||
| CVE-2025-63607 | Med | 0.40 | 6.1 | 0.00 | Aug 31, 2026 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser. | ||
| CVE-2026-82905 | Med | 0.41 | 6.3 | 0.00 | Aug 31, 2026 | A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be… | ||
| CVE-2026-82835 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been… | ||
| CVE-2026-82834 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the… |
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
- risk 0.46cvss 8.1epss 0.00
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed…
- risk 0.46cvss 8.1epss 0.01
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar,…
- risk 0.28cvss 5.4epss 0.00
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing…
- risk 0.49cvss 8.6epss 0.01
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates…
- risk 0.28cvss 5.4epss 0.00
@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine…
- risk 0.26cvss —epss 0.01
Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path…
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
- risk 0.65cvss 10.0epss 0.01
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
- risk 0.41cvss 6.3epss 0.00
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
- risk 0.49cvss 7.5epss 0.00
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
- risk 0.27cvss 5.3epss 0.00
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in…
- risk 0.64cvss 9.8epss 0.02
An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.
- risk 0.49cvss 7.5epss 0.01
A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME…
- risk 0.46cvss —epss 0.01
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's…
- risk 0.38cvss —epss 0.01
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Kirby\Filesystem\Dir::realpath() and…
- risk 0.42cvss 6.5epss 0.00
XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.
- risk 0.53cvss 8.1epss 0.00
The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence,…
- risk 0.39cvss —epss 0.00
Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Api\Upload::processChunk() persisted chunk…
- risk 0.38cvss —epss 0.01
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used…
- risk 0.46cvss 8.1epss 0.01
Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email…
- risk 0.48cvss —epss 0.01
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs…
- risk 0.48cvss —epss 0.01
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to…
- risk 0.46cvss —epss 0.01
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port.…
- risk 0.46cvss —epss 0.01
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire…
- risk 0.42cvss —epss 0.00
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session…
- risk 0.42cvss 7.5epss 0.00
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against…
- risk 0.22cvss 4.4epss 0.00
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/SingleBase64Image.php methods…
- risk 0.21cvss 4.3epss 0.00
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal…
- risk 0.21cvss 4.3epss 0.00
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID belonging to another user. The write is accepted, and later the…
- risk 0.64cvss 9.8epss 0.00
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
- risk 0.40cvss 6.1epss 0.00
TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be…
- risk 0.35cvss 5.4epss 0.00
A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been…
- risk 0.35cvss 5.4epss 0.00
A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the…