Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

454 CVEs · published 2026-09-01 to 2026-09-01

CVEs (454)

Showing 301–325 of 454

CVE ID Severity Patch CVSS Published Description
CVE-2026-51757 NONE — 2026-09-01 Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflo…
CVE-2026-51756 MEDIUM 5.9 2026-09-01 Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgr…
CVE-2026-51754 NONE — 2026-09-01 Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state v…
CVE-2026-51752 MEDIUM 5.3 2026-09-01 Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the…
CVE-2026-51751 NONE — 2026-09-01 Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local …
CVE-2026-51750 NONE — 2026-09-01 Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channe…
CVE-2026-51748 MEDIUM 5.9 2026-09-01 Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory recor…
CVE-2026-19513 HIGH 8.1 2026-09-01 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-f…
CVE-2026-18808 CRITICAL 9.8 2026-09-01 Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i…
CVE-2026-18210 CRITICAL Patched 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T…
CVE-2026-16675 NONE — 2026-09-01 A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol…
CVE-2026-13348 NONE — 2026-09-01 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by perfor…
CVE-2026-13337 NONE — 2026-09-01 CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into …
CVE-2026-13336 NONE — 2026-09-01 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system…
CVE-2026-12663 NONE — 2026-09-01 A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb…
CVE-2026-12661 NONE — 2026-09-01 A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to th…
CVE-2025-12768 NONE — 2026-09-01 A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe…
CVE-2024-14047 HIGH 7.2 2026-09-01 A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex…
CVE-2024-10085 NONE — 2026-09-01 CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large numb…
CVE-2026-84235 NONE — 2026-09-01 A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a …
CVE-2026-84149 NONE — 2026-09-01 This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could…
CVE-2026-84148 NONE — 2026-09-01 This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit …
CVE-2026-84147 NONE — 2026-09-01 This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attac…
CVE-2026-84145 HIGH Patched 7.5 2026-09-01 Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another secur…
CVE-2026-84144 NONE Patched — 2026-09-01 Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and …