Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51748 | MEDIUM | 5.9 | 2026-09-01 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory recor… | |
| CVE-2026-51750 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channe… | |
| CVE-2026-51751 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local … | |
| CVE-2026-51752 | MEDIUM | 5.3 | 2026-09-01 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the… | |
| CVE-2026-51754 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state v… | |
| CVE-2026-51756 | MEDIUM | 5.9 | 2026-09-01 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgr… | |
| CVE-2026-51757 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflo… | |
| CVE-2026-51760 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity acro… | |
| CVE-2026-51761 | MEDIUM | 5.3 | 2026-09-01 | Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a cr… | |
| CVE-2026-51762 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state an… | |
| CVE-2026-51763 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sen… | |
| CVE-2026-51764 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking … | |
| CVE-2026-51765 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor recor… | |
| CVE-2026-51766 | HIGH | 7.5 | 2026-09-01 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan… | |
| CVE-2026-51767 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device… | |
| CVE-2026-51768 | HIGH | 7.5 | 2026-09-01 | Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the mast… | |
| CVE-2026-51769 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check work… | |
| CVE-2026-51770 | CRITICAL | 9.8 | 2026-09-01 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS sett… | |
| CVE-2026-51788 | HIGH | 7.5 | 2026-09-01 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component | |
| CVE-2026-51934 | CRITICAL | 9.8 | 2026-09-01 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdl… | |
| CVE-2026-51956 | HIGH | 8.1 | 2026-09-01 | A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's c… | |
| CVE-2026-51974 | HIGH | 8.8 | 2026-09-01 | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrar… | |
| CVE-2026-52022 | HIGH | Patched | 7.5 | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components |
| CVE-2026-52023 | NONE | — | 2026-09-01 | An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_p… | |
| CVE-2026-52111 | CRITICAL | 9.8 | 2026-09-01 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey |