CVE-2025-15630 - Device Provisioning Race Condition in TP-Link Omada Adoption Workflow
CVE ID :CVE-2025-15630
Published : Aug. 3, 2026, 7:16 p.m. | 44 minutes ago
Description :A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15630
Published : Aug. 3, 2026, 7:16 p.m. | 44 minutes ago
Description :A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15631 - Weak Credential Storage in TP-Link Omada Devices
CVE ID :CVE-2025-15631
Published : Aug. 3, 2026, 7:16 p.m. | 44 minutes ago
Description :A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15631
Published : Aug. 3, 2026, 7:16 p.m. | 44 minutes ago
Description :A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18614 - GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection
CVE ID :CVE-2026-18614
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18614
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18615 - GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection
CVE ID :CVE-2026-18615
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18615
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18616 - GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
CVE ID :CVE-2026-18616
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18616
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-38444 - osTicket Stored Cross-Site Scripting
CVE ID :CVE-2026-38444
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-38444
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-38446 - osTicket Stored Cross-Site Scripting
CVE ID :CVE-2026-38446
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-38446
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-38447 - osTicket API Key Cryptographic Weakness
CVE ID :CVE-2026-38447
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-38447
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59912 - Dell Display and Peripheral Manager Improper Access Control Vulnerability
CVE ID :CVE-2026-59912
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59912
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59913 - Dell Display and Peripheral Manager Privilege Escalation Vulnerability
CVE ID :CVE-2026-59913
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59913
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18632 - langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
CVE ID :CVE-2026-18632
Published : Aug. 3, 2026, 7:30 p.m. | 30 minutes ago
Description :A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18632
Published : Aug. 3, 2026, 7:30 p.m. | 30 minutes ago
Description :A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66312 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE ID :CVE-2026-66312
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66312
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66313 - Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE ID :CVE-2026-66313
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66313
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66314 - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE ID :CVE-2026-66314
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66314
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66315 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE ID :CVE-2026-66315
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66315
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66316 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-66316
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66316
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65802 - Microsoft Edge for Android Information Disclosure Vulnerability
CVE ID :CVE-2026-65802
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65802
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65804 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-65804
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65804
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66311 - Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE ID :CVE-2026-66311
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66311
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66317 - Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE ID :CVE-2026-66317
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66317
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66322 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-66322
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66322
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...