Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-73819 CRITICAL 9.8 2026-08-31 The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential …
CVE-2026-51709 CRITICAL 9.8 2026-08-31 Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sen…
CVE-2026-51715 CRITICAL 9.8 2026-08-31 Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a cr…
CVE-2026-51718 CRITICAL 9.8 2026-08-31 Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sen…
CVE-2026-51699 CRITICAL 9.8 2026-08-31 Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted PO…
CVE-2026-51705 CRITICAL 9.8 2026-08-31 Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted …
CVE-2026-51708 CRITICAL 9.8 2026-08-31 Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafte…
CVE-2026-51696 CRITICAL 9.8 2026-08-31 Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a…
CVE-2026-51691 CRITICAL 9.8 2026-08-31 Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow v…
CVE-2026-51693 CRITICAL 9.8 2026-08-31 Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted …
CVE-2026-51684 CRITICAL 9.8 2026-08-31 Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via …
CVE-2026-51686 CRITICAL 9.8 2026-08-31 Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks vi…
CVE-2026-51674 CRITICAL 9.8 2026-08-31 Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a…
CVE-2026-51670 CRITICAL 9.8 2026-08-31 Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgra…
CVE-2026-82858 CRITICAL Patched 9.8 2026-08-31 @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated…
CVE-2026-82859 CRITICAL 9.8 2026-08-31 hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM bounda…
CVE-2026-82860 CRITICAL Patched 9.8 2026-08-31 @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equiv…
CVE-2026-82854 CRITICAL Patched 9.8 2026-08-31 Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a …
CVE-2026-82855 CRITICAL Patched 9.8 2026-08-31 @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppr…
CVE-2026-82856 CRITICAL Patched 9.8 2026-08-31 @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:Stri…
CVE-2026-82857 CRITICAL 9.8 2026-08-31 hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles with…
CVE-2026-58574 CRITICAL 9.8 2026-08-31 Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interfac…
CVE-2026-15980 CRITICAL 9.8 2026-08-30 The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_li…
CVE-2026-15369 CRITICAL 9.8 2026-08-29 The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the p…
CVE-2026-82460 CRITICAL Patched 9.8 2026-08-29 Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization…