Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 13,088 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73819 | CRITICAL | 9.8 | 2026-08-31 | The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential … | |
| CVE-2026-51709 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sen… | |
| CVE-2026-51715 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a cr… | |
| CVE-2026-51718 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sen… | |
| CVE-2026-51699 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted PO… | |
| CVE-2026-51705 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted … | |
| CVE-2026-51708 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafte… | |
| CVE-2026-51696 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a… | |
| CVE-2026-51691 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow v… | |
| CVE-2026-51693 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted … | |
| CVE-2026-51684 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via … | |
| CVE-2026-51686 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks vi… | |
| CVE-2026-51674 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a… | |
| CVE-2026-51670 | CRITICAL | 9.8 | 2026-08-31 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgra… | |
| CVE-2026-82858 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated… |
| CVE-2026-82859 | CRITICAL | 9.8 | 2026-08-31 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM bounda… | |
| CVE-2026-82860 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equiv… |
| CVE-2026-82854 | CRITICAL | Patched | 9.8 | 2026-08-31 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a … |
| CVE-2026-82855 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppr… |
| CVE-2026-82856 | CRITICAL | Patched | 9.8 | 2026-08-31 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:Stri… |
| CVE-2026-82857 | CRITICAL | 9.8 | 2026-08-31 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles with… | |
| CVE-2026-58574 | CRITICAL | 9.8 | 2026-08-31 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interfac… | |
| CVE-2026-15980 | CRITICAL | 9.8 | 2026-08-30 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_li… | |
| CVE-2026-15369 | CRITICAL | 9.8 | 2026-08-29 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the p… | |
| CVE-2026-82460 | CRITICAL | Patched | 9.8 | 2026-08-29 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization… |