CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2026-52295

    Last Modified: 7 Sept 2026

    Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component

    Published: 1 Sept 2026
    6.4
    Medium

    CVE-2026-84470

    Last Modified: 4 Sept 2026

    A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51767

    Last Modified: 4 Sept 2026

    Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-52132

    Last Modified: 4 Sept 2026

    llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.

    Published: 1 Sept 2026
    5.4
    Medium

    CVE-2026-84232

    Last Modified: 3 Sept 2026

    A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51765

    Last Modified: 3 Sept 2026

    Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51769

    Last Modified: 3 Sept 2026

    Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-52023

    Last Modified: 10 Sept 2026

    An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-52130

    Last Modified: 4 Sept 2026

    llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-52022

    Last Modified: 4 Sept 2026

    An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-51788

    Last Modified: 3 Sept 2026

    An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component

    Published: 1 Sept 2026
    5.3
    Medium

    CVE-2026-51761

    Last Modified: 2 Sept 2026

    Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    5.9
    Medium

    CVE-2026-51742

    Last Modified: 2 Sept 2026

    Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 1 Sept 2026
    5.3
    Medium

    CVE-2026-53682

    Last Modified: 4 Sept 2026

    An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-52131

    Last Modified: 4 Sept 2026

    llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-52111

    Last Modified: 3 Sept 2026

    An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey

    Published: 1 Sept 2026
    8.1
    High

    CVE-2026-51956

    Last Modified: 3 Sept 2026

    A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51770

    Last Modified: 3 Sept 2026

    Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-51768

    Last Modified: 3 Sept 2026

    Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51764

    Last Modified: 3 Sept 2026

    Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51763

    Last Modified: 3 Sept 2026

    Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    7.5
    High

    CVE-2026-51766

    Last Modified: 2 Sept 2026

    Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51762

    Last Modified: 3 Sept 2026

    Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51747

    Last Modified: 3 Sept 2026

    Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    8.1
    High

    CVE-2026-84218

    Last Modified: 3 Sept 2026

    A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.

    Published: 1 Sept 2026
    6.5
    Medium

    CVE-2026-11873

    Last Modified: 4 Sept 2026

    An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.

    Published: 1 Sept 2026
    5.3
    Medium

    CVE-2026-51745

    Last Modified: 1 Sept 2026

    Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    5.9
    Medium

    CVE-2026-51748

    Last Modified: 2 Sept 2026

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.1
    Critical

    CVE-2026-51743

    Last Modified: 2 Sept 2026

    Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51744

    Last Modified: 3 Sept 2026

    Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51741

    Last Modified: 3 Sept 2026

    Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 1 Sept 2026
    5.9
    Medium

    CVE-2026-51756

    Last Modified: 2 Sept 2026

    Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51750

    Last Modified: 3 Sept 2026

    Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51751

    Last Modified: 3 Sept 2026

    Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51754

    Last Modified: 3 Sept 2026

    Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51757

    Last Modified: 3 Sept 2026

    Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51760

    Last Modified: 3 Sept 2026

    Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    8.8
    High

    CVE-2026-51974

    Last Modified: 3 Sept 2026

    An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata of an uploaded image file.

    Published: 1 Sept 2026
    9.8
    Critical

    CVE-2026-51934

    Last Modified: 3 Sept 2026

    Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function

    Published: 1 Sept 2026
    5.3
    Medium

    CVE-2026-51752

    Last Modified: 2 Sept 2026

    Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.

    Published: 1 Sept 2026
    8.6
    High

    CVE-2026-83524

    Last Modified: 1 Sept 2026

    A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    9.3
    Critical

    CVE-2026-82971

    Last Modified: 1 Sept 2026

    A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 31 Aug 2026
    5.5
    Medium

    CVE-2026-82957

    Last Modified: 1 Sept 2026

    A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    8.6
    High

    CVE-2026-82954

    Last Modified: 31 Aug 2026

    A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    6.9
    Medium

    CVE-2026-82398

    Last Modified: 1 Sept 2026

    pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0.

    Published: 31 Aug 2026
    5.5
    Medium

    CVE-2026-82922

    Last Modified: 1 Sept 2026

    A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-82397

    Last Modified: 2 Sept 2026

    Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, so an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection. The body is bounded only by max_buffer_size, which defaults to 104857600 bytes. This issue is fixed in version 6.5.8.

    Published: 31 Aug 2026
    5.4
    Medium

    CVE-2026-82396

    Last Modified: 1 Sept 2026

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administration variant to honor the inline query parameter for scriptable MIME types. The vulnerable stored Content-Type values include text/html, application/xhtml+xml, text/xml, and application/xml. An attacker with media upload permission can store an HTML, XHTML, or XML document and create a link using inline=1, causing the application to return the file on the Sulu origin instead of forcing Content-Disposition attachment. When an authenticated victim opens the link, attacker-controlled JavaScript can execute with the victim's Sulu-origin session and can read data or perform actions as that victim. This issue is fixed in versions 2.6.25 and 3.0.8.

    Published: 31 Aug 2026
    4.6
    Medium

    CVE-2026-77353

    Last Modified: 3 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequences in subscription names or notes. Because the input validation layer only encodes HTML metacharacters but never strips newlines, and the export layer decodes those entities back before writing iCal output, an attacker with any valid account can craft a subscription whose name breaks out of the current VEVENT block and inserts fully attacker-controlled calendar events — including spoofed organizers, arbitrary email addresses in ATTENDEE properties, and misleading event content — into any calendar application subscribed to that feed. This issue has been patched in version 5.0.0.

    Published: 31 Aug 2026
    4.3
    Medium

    CVE-2026-77352

    Last Modified: 1 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to internal/link-local addresses, by setting the SMTP host of their personal email notifications to an internal IP. The per-user notification settings endpoint (endpoints/notifications/saveemailnotifications.php) performs no SSRF validation, and the notification cron (endpoints/cronjobs/sendnotifications.php) feeds that user-controlled host straight into PHPMailer ($mail->Host = $email['smtpAddress']). When the user's subscription notification fires, the server connects to the chosen host:port. This issue has been patched in version 5.0.0.

    Published: 31 Aug 2026