Common Vulnerabilities and Exposures (CVE)

CVE-2026-19635

Aug 14, 2026 17:45:27 UTC

A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim i...

CVE-2026-49282

Aug 14, 2026 17:44:44 UTC

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing...

CVE-2026-54481

Aug 14, 2026 17:44:39 UTC

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

CVE-2026-19631

Aug 14, 2026 17:43:45 UTC

A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.

CVE-2026-58420

Aug 14, 2026 17:43:31 UTC

Local File Inclusion via file:// URI in Migration Restore

CVE-2026-55982

Aug 14, 2026 17:42:09 UTC

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

CVE-2026-55984

Aug 14, 2026 17:40:25 UTC

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

CVE-2026-19680

Aug 14, 2026 17:39:21 UTC

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

CVE-2026-57886

Aug 14, 2026 17:38:03 UTC

Cross-repository issue/comment attachment re-linking can expose private attachment content

CVE-2026-19845

Aug 14, 2026 17:37:51 UTC

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to st...

CVE-2026-73849

Aug 14, 2026 17:37:20 UTC

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A r...

CVE-2026-57894

Aug 14, 2026 17:36:49 UTC

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

CVE-2026-19679

Aug 14, 2026 17:35:46 UTC

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.

CVE-2026-58314

Aug 14, 2026 17:35:42 UTC

Two SSRF findings in Gitea 1.26.2

CVE-2026-58417

Aug 14, 2026 17:34:38 UTC

REST API exposes organization membership of private organizations to public