Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 31 August 2026

RSS

928 vulnerabilities published on 31 August 2026

Severity:
QVidium Opera11 allows remote command execution via net_tr.cgi
CVE-2026-82971
The web component net_tr.cgi in QVidium Opera11 can be tricked into running commands you did not intend by sending a specially crafted IP address value. This can be done from anywhere on the internet ...
9.3
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-81780
10.0
WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability
CVE-2026-81779
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.
10.0
WP Cookie Notice plugin lets attackers upload malicious files
CVE-2026-82970
The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin (versions up to 4.4.1) allows anyone to upload a file of any type. An attacker could place a malicious script on your WordPress site, givi...
10.0
Tenda AC18 router allows remote access without login
CVE-2026-82695
The Tenda AC18 router version 15.03.05.19 has a flaw that lets anyone connect to its telnet interface without needing a username or password. This could let attackers control the device from anywhere....
9.3
Tenda AC1206 router allows unauthenticated web access
CVE-2026-82694
The web management page of the Tenda AC1206 router (firmware version 15.03.06.23) does not properly check who is using it. This lets anyone on the network or internet reach the router’s settings witho...
9.3
Tenda AC1206 router allows remote login bypass
CVE-2026-82693
The web interface of the Tenda AC1206 router (firmware version 15.03.06.23) contains a flaw that lets anyone on the network send a special request and skip the login step. This can be exploited from o...
9.3
RedPort Optimizer wXa-223 enables remote command execution
CVE-2026-83524
Versions wXa-203, wXa-213 and wXa-223 of RedPort Optimizer (up to the July 2026 release) contain a flaw in the system clock component that lets an attacker send specially‑crafted requests to the file ...
8.6
Dokploy lets attackers read/write arbitrary server files
CVE-2026-82954
Versions of Dokploy up to 0.29.7 let a remote user change a setting so the system writes files in locations you didn’t intend. This can give an attacker the ability to view or alter any file on the se...
8.6
MCPHub lets logged-in user run any command
CVE-2026-79748
In versions of MCPHub before 0.12.15, any user who can log in (even without admin rights) could add or change a server entry and cause the software to start any program it wants. This lets the attacke...
9.9
D-Link DNS-340L/345 allows remote command execution
CVE-2026-82692
The web management interface on D-Link DNS-340L and DNS-345 devices can be tricked into running operating system commands by sending specially crafted input. This can be done from anywhere on the netw...
8.6
D-Link NAS devices allow remote command execution
CVE-2026-82689
The D-Link DNS‑320L, DNS‑327L, DNS‑340L and DNS‑345 storage units let an attacker send specially crafted data to a web page (isomount_mgr.cgi) and cause the device to run arbitrary commands. This can ...
8.6
ToolJet before 3.16.208 lets any logged‑in user edit other companies' data
CVE-2026-82874
If you run ToolJet versions older than 3.16.208, a logged‑in Builder user can access data belonging to other organisations because the software does not check which company the user belongs to. This m...
2.4
TOTOLINK NR1800X router can be remotely crashed
CVE-2026-82616
The router’s web interface has a flaw that lets an attacker send a specially crafted file name and overflow the memory stack. This can be triggered over the network, potentially causing the device to ...
8.6
D-Link DIR-825M LTE firmware upgrade can be hijacked remotely
CVE-2026-82593
The router’s LTE module update feature in version 1.1.8 can be fooled into running unwanted code when an attacker sends a specially crafted update link. This could let a remote attacker take control o...
8.6
WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability
CVE-2026-82226
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
9.8
Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att...
CVE-2026-51738
9.8
Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a...
CVE-2026-51734
9.8
Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att...
CVE-2026-51733
9.8
OpenTelemetry Java: Unrestricted Code Can Run on Your Server
GHSA-xw7x-h9fj-p2c7 CVE-2026-33701 ROOT-APP-MAVEN-CVE-2026-33701
If you use OpenTelemetry Java with a remote management port, a malicious person could potentially take control of your server by sending it a specially crafted message. This only happens if you have a...
9.3
TOTOLINK T6 router lets anyone upload malicious firmware
CVE-2026-51728
The router's firmware‑upload feature does not verify the user who sends the request. An attacker could send a specially crafted file and replace the router’s software, potentially taking control of th...
9.8
TOTOLINK T6 router lets anyone delete QoS rules
CVE-2026-51724
The TOTOLINK T6 device running version 4.1.5 allows anyone on the network to send a special request that erases its Smart QoS (traffic‑priority) settings without logging in. This could cause important...
9.8
Ebyte NE2-D11 weak hash lets attackers bypass login
CVE-2026-76133
The Ebyte NE2-D11 device uses an old, insecure method for checking passwords. This can let a hacker trick the device into thinking they are authorized and gain access. Update the device’s software or ...
9.3
Ebyte NE2-D11 allows admin changes without proper login
CVE-2026-73819
The configuration tool for the Ebyte NE2-D11 lets anyone on the same network change important settings or reset passwords without proving who they are. This could let an attacker lock out legitimate m...
9.3
TOTOLINK T6 router lets anyone delete MAC filter rules
CVE-2026-51715
The T6 router’s software does not properly verify who can change its device‑address filter list. This allows anyone on the network to send a simple request that removes those filters, letting unauthor...
9.8