-
CVE-2026-50986
•
published on July 31, 2026
PrestaShop module, totadministrativemandate 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link.
-
CVE-2026-51785
•
published on July 31, 2026
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
-
CVE-2026-51953
•
published on July 31, 2026
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components
-
CVE-2026-52134
•
published on July 31, 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.
-
CVE-2026-52232
•
published on July 31, 2026
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.
-
CVE-2026-52371
•
published on July 31, 2026
A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.
-
CVE-2026-67822
•
published on July 31, 2026
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
-
CVE-2026-61893
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past the end of the heap-allocated message buffer.
-
CVE-2026-61893
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past the end of the heap-allocated message buffer.
-
CVE-2026-61893
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past the end of the heap-allocated message buffer.
-
CVE-2026-61893
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past the end of the heap-allocated message buffer.
-
CVE-2026-63033
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.
-
CVE-2026-63033
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.
-
CVE-2026-63033
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.
-
CVE-2026-63033
•
published on July 30, 2026
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.
-
CVE-2026-10031
•
published on July 30, 2026
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.
-
CVE-2026-10031
•
published on July 30, 2026
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.
-
CVE-2026-10031
•
published on July 30, 2026
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.
-
CVE-2026-10031
•
published on July 30, 2026
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.
-
CVE-2026-66720
•
published on July 30, 2026
The GOOSE subscriber component improperly validates the UTC timestamp
field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2
multicast messages. A specially crafted GOOSE frame containing an
undersized timestamp field can trigger a heap out-of-bounds read during
message processing, causing the process to crash and resulting in a
denial-of-service condition.