Search
34,865 CVEs · Critical severity
CVEs (34,865, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 34,865 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-53552 | CRITICAL | 9.6 | 2026-08-31 | Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/a… | |
| CVE-2026-79748 | CRITICAL | Patched | 9.9 | 2026-08-31 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to ve… |
| CVE-2026-51730 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a craft… | |
| CVE-2026-51729 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via s… | |
| CVE-2026-51728 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sen… | |
| CVE-2026-51726 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending… | |
| CVE-2026-51725 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a craf… | |
| CVE-2026-51724 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafte… | |
| CVE-2026-51723 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending… | |
| CVE-2026-51722 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-contr… | |
| CVE-2026-51721 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a craf… | |
| CVE-2026-51720 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via send… | |
| CVE-2026-76133 | CRITICAL | 9.8 | 2026-08-31 | The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the… | |
| CVE-2026-73819 | CRITICAL | 9.8 | 2026-08-31 | The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential … | |
| CVE-2026-51718 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sen… | |
| CVE-2026-51717 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending … | |
| CVE-2026-51715 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a cr… | |
| CVE-2026-51713 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a c… | |
| CVE-2026-51711 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending… | |
| CVE-2026-51710 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sendi… | |
| CVE-2026-51709 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sen… | |
| CVE-2026-51708 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafte… | |
| CVE-2026-51705 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted … | |
| CVE-2026-51701 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending… | |
| CVE-2026-51700 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a… |