CVE ID :CVE-2026-55848 Published : Aug. 28, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16,…
CVE-2026-55764 – Klever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
CVE ID :CVE-2026-55764 Published : Aug. 28, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role…
CVE-2026-81532 – BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corruption
CVE ID :CVE-2026-81532 Published : Aug. 28, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver…
CVE-2026-75118 – http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow
CVE ID :CVE-2026-75118 Published : Aug. 28, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient…
CVE-2026-55763 – Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
CVE ID :CVE-2026-55763 Published : Aug. 28, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls…
CVE-2026-78239 – Xiiaozet LK100W Missing Authentication for Critical Function
CVE ID :CVE-2026-78239 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to…
CVE-2026-78037 – Xiiaozet LK100W OS Command Injection
CVE ID :CVE-2026-78037 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be…
CVE-2026-77977 – Ebyte NE2-D11 Missing Authentication for Critical Function
CVE ID :CVE-2026-77977 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :Ebyte gateway product’s vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default…
CVE-2026-77358 – cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_close()
CVE ID :CVE-2026-77358 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the…
CVE-2026-76945 – Ebyte NE2-D11 Use of Client-Side Authentication
CVE ID :CVE-2026-76945 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or…