Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,684 CVEs · Critical severity

CVEs (3,684, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 176–200 of 3,684 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-51767 CRITICAL 9.8 2026-09-01 Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device…
CVE-2026-18931 CRITICAL 9.1 2026-09-01 Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. Th…
CVE-2026-78012 CRITICAL 9.8 2026-09-01 An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generat…
CVE-2026-51765 CRITICAL 9.8 2026-09-01 Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor recor…
CVE-2026-51764 CRITICAL 9.8 2026-09-01 Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking …
CVE-2026-51763 CRITICAL 9.8 2026-09-01 Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sen…
CVE-2026-51762 CRITICAL 9.8 2026-09-01 Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state an…
CVE-2026-51760 CRITICAL 9.8 2026-09-01 Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity acro…
CVE-2026-51757 CRITICAL 9.8 2026-09-01 Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflo…
CVE-2026-51754 CRITICAL 9.8 2026-09-01 Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state v…
CVE-2026-51751 CRITICAL 9.8 2026-09-01 Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local …
CVE-2026-51750 CRITICAL 9.8 2026-09-01 Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channe…
CVE-2026-18808 CRITICAL 9.8 2026-09-01 Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i…
CVE-2026-18210 CRITICAL Patched 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and T…
CVE-2026-84143 CRITICAL Patched 9.8 2026-09-01 Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another secur…
CVE-2026-84142 CRITICAL Patched 9.8 2026-09-01 Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enoug…
CVE-2026-84141 CRITICAL Patched 9.8 2026-09-01 Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84140 CRITICAL Patched 9.8 2026-09-01 Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84135 CRITICAL Patched 9.8 2026-09-01 Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84134 CRITICAL Patched 9.8 2026-09-01 Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84133 CRITICAL Patched 9.8 2026-09-01 Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84129 CRITICAL Patched 9.8 2026-09-01 Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84121 CRITICAL Patched 9.6 2026-09-01 Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2,…
CVE-2026-84119 CRITICAL Patched 9.6 2026-09-01 Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.…
CVE-2026-51747 CRITICAL 9.8 2026-09-01 Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward …