| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-51635 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51634 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51633 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51632 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51631 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51630 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51629 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51628 | Cri | 0.59 | 9.1 | 0.01 | Aug 28, 2026 | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51627 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51626 | Cri | 0.59 | 9.1 | 0.01 | Aug 28, 2026 | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51625 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51624 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51623 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51622 | Cri | 0.59 | 9.1 | 0.01 | Aug 28, 2026 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51621 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51620 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51619 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51618 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51617 | Hig | 0.49 | 7.5 | 0.00 | Aug 28, 2026 | Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected… | ||
| CVE-2026-51616 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51615 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51614 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51613 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51611 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2026 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. | ||
| CVE-2026-51610 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||
| CVE-2026-51376 | Med | 0.35 | 6.5 | 0.00 | Aug 28, 2026 | An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache | ||
| CVE-2026-50980 | Med | 0.40 | 6.1 | 0.00 | Aug 28, 2026 | Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record | ||
| CVE-2026-39071 | Med | 0.35 | 5.4 | 0.00 | Aug 28, 2026 | WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account. | ||
| CVE-2026-39070 | Med | 0.31 | 4.8 | 0.00 | Aug 28, 2026 | WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account. | ||
| CVE-2026-82330 | Med | 0.40 | 6.1 | 0.00 | Aug 28, 2026 | A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an… | ||
| CVE-2026-82328 | Med | 0.40 | 6.1 | 0.00 | Aug 28, 2026 | A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap… | ||
| CVE-2026-82327 | Med | 0.36 | 5.5 | 0.00 | Aug 28, 2026 | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data… | ||
| CVE-2026-82324 | Med | 0.40 | 6.1 | 0.00 | Aug 28, 2026 | A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size… | ||
| CVE-2026-82227 | Hig | 0.55 | 8.5 | 0.00 | Aug 28, 2026 | Contributor SQL Injection in WPBulky <= 1.2.2 versions. | ||
| CVE-2026-82220 | Med | 0.34 | 5.3 | 0.00 | Aug 28, 2026 | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. | ||
| CVE-2026-82181 | Med | 0.36 | 5.5 | 0.00 | Aug 28, 2026 | Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files. | ||
| CVE-2026-82112 | Low | 0.16 | 3.5 | 0.00 | Aug 28, 2026 | A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called… | ||
| CVE-2026-82078 | Cri | 0.67 | 9.1 | 0.61 | KEV | Aug 28, 2026 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an… | |
| CVE-2026-81767 | Hig | 0.49 | 7.5 | 0.00 | Aug 28, 2026 | Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | ||
| CVE-2026-81761 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. | ||
| CVE-2026-81760 | Hig | 0.46 | 7.1 | 0.00 | Aug 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | ||
| CVE-2026-81759 | Med | 0.35 | 5.4 | 0.00 | Aug 28, 2026 | Contributor Broken Access Control in WpEvently <= 5.5.0 versions. | ||
| CVE-2026-81757 | Hig | 0.47 | 7.2 | 0.01 | Aug 28, 2026 | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | ||
| CVE-2026-81578 | Cri | 0.72 | 9.8 | 0.85 | KEV | Aug 28, 2026 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access… | |
| CVE-2026-81341 | Med | 0.35 | 6.5 | 0.00 | Aug 28, 2026 | wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to… | ||
| CVE-2026-81299 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. | ||
| CVE-2026-81285 | Hig | 0.49 | 7.5 | 0.00 | Aug 28, 2026 | Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. | ||
| CVE-2026-81284 | Med | 0.28 | 4.3 | 0.00 | Aug 28, 2026 | Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. | ||
| CVE-2026-81020 | Hig | 0.41 | 7.4 | 0.00 | Aug 28, 2026 | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM… | ||
| CVE-2026-81019 | Hig | 0.41 | 7.4 | 0.00 | Aug 28, 2026 | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a… |
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.59cvss 9.1epss 0.01
Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.59cvss 9.1epss 0.01
Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.59cvss 9.1epss 0.01
Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected…
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.
- risk 0.28cvss 4.3epss 0.00
Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- risk 0.35cvss 6.5epss 0.00
An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache
- risk 0.40cvss 6.1epss 0.00
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record
- risk 0.35cvss 5.4epss 0.00
WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.
- risk 0.31cvss 4.8epss 0.00
WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account.
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an…
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data…
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size…
- risk 0.55cvss 8.5epss 0.00
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
- risk 0.36cvss 5.5epss 0.00
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
- risk 0.16cvss 3.5epss 0.00
A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called…
- risk 0.67cvss 9.1epss 0.61
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
- risk 0.28cvss 4.3epss 0.00
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
- risk 0.35cvss 5.4epss 0.00
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
- risk 0.47cvss 7.2epss 0.01
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
- risk 0.72cvss 9.8epss 0.85
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access…
- risk 0.35cvss 6.5epss 0.00
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to…
- risk 0.28cvss 4.3epss 0.00
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
- risk 0.28cvss 4.3epss 0.00
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
- risk 0.41cvss 7.4epss 0.00
wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM…
- risk 0.41cvss 7.4epss 0.00
wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a…