Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-51752 MEDIUM 5.3 2026-09-01 Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the…
CVE-2026-51754 CRITICAL 9.8 2026-09-01 Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state v…
CVE-2026-51756 MEDIUM 5.9 2026-09-01 Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgr…
CVE-2026-51757 CRITICAL 9.8 2026-09-01 Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflo…
CVE-2026-51760 CRITICAL 9.8 2026-09-01 Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity acro…
CVE-2026-51761 MEDIUM 5.3 2026-09-01 Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a cr…
CVE-2026-51762 CRITICAL 9.8 2026-09-01 Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state an…
CVE-2026-51763 CRITICAL 9.8 2026-09-01 Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sen…
CVE-2026-51764 CRITICAL 9.8 2026-09-01 Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking …
CVE-2026-51765 CRITICAL 9.8 2026-09-01 Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor recor…
CVE-2026-51766 HIGH 7.5 2026-09-01 Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan…
CVE-2026-58571 HIGH 8.8 2026-09-01 Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitr…
CVE-2026-58572 HIGH 8.8 2026-09-01 Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary cod…
CVE-2026-79684 HIGH 8.8 2026-09-01 Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass …
CVE-2026-80047 HIGH 7.8 2026-09-01 A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using Genera&hellip;
CVE-2026-84109 MEDIUM 6.3 2026-09-01 A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a mani&hellip;
CVE-2026-84218 HIGH 8.1 2026-09-01 A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to &hellip;
CVE-2026-9621 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the &hellip;
CVE-2026-9622 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, r&hellip;
CVE-2026-9624 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length valida&hellip;
CVE-2026-9625 NONE &mdash; 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to c&hellip;
CVE-2026-9633 NONE &mdash; 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or&hellip;
CVE-2026-9634 NONE &mdash; 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or &hellip;
CVE-2026-9637 NONE &mdash; 2026-09-01 A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length durin&hellip;
CVE-2026-18630 HIGH 8.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Managemen&hellip;