Search
7,875 CVEs · Critical severity
CVEs (7,875, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 7,875 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-51699 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted PO… | |
| CVE-2026-51698 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a cr… | |
| CVE-2026-51152 | CRITICAL | 9.1 | 2026-08-31 | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPReques… | |
| CVE-2026-82970 | CRITICAL | 10.0 | 2026-08-31 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue… | |
| CVE-2026-59111 | CRITICAL | 9.3 | 2026-08-31 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on M… | |
| CVE-2026-51697 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a … | |
| CVE-2026-51696 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a… | |
| CVE-2026-51693 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted … | |
| CVE-2026-51692 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access … | |
| CVE-2026-51691 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow v… | |
| CVE-2026-51690 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via… | |
| CVE-2026-51689 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via… | |
| CVE-2026-51687 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access … | |
| CVE-2026-51686 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks vi… | |
| CVE-2026-51684 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via … | |
| CVE-2026-51681 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a … | |
| CVE-2026-51680 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST r… | |
| CVE-2026-51679 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sendin… | |
| CVE-2026-51677 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted… | |
| CVE-2026-51676 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sendin… | |
| CVE-2026-51675 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a craf… | |
| CVE-2026-51674 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a… | |
| CVE-2026-51672 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sendi… | |
| CVE-2026-51670 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgra… | |
| CVE-2026-51669 | CRITICAL | 9.1 | 2026-08-31 | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via… |