Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51622 | UNKNOWN | — | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51621 | UNKNOWN | — | Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51620 | UNKNOWN | — | Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51619 | UNKNOWN | — | Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51618 | UNKNOWN | — | Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51617 | UNKNOWN | — | Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial … | Aug 28, 2026 |
| CVE-2026-51616 | UNKNOWN | — | Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51615 | UNKNOWN | — | Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51614 | UNKNOWN | — | Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a … | Aug 28, 2026 |
| CVE-2026-51613 | UNKNOWN | — | Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51611 | UNKNOWN | — | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. | Aug 28, 2026 |
| CVE-2026-51610 | UNKNOWN | — | Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51376 | UNKNOWN | — | An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh … | Aug 28, 2026 |
| CVE-2026-50980 | UNKNOWN | — | Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via … | Aug 28, 2026 |
| CVE-2026-39071 | UNKNOWN | — | WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) … | Aug 28, 2026 |
| CVE-2026-39070 | UNKNOWN | — | WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit … | Aug 28, 2026 |
| CVE-2026-82330 | MEDIUM | 6.1 | A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly … | Aug 28, 2026 |
| CVE-2026-82328 | MEDIUM | 6.1 | A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the … | Aug 28, 2026 |
| CVE-2026-82327 | MEDIUM | 5.5 | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache … | Aug 28, 2026 |
| CVE-2026-82324 | MEDIUM | 6.1 | A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate … | Aug 28, 2026 |
| CVE-2026-82227 | HIGH | 8.5 | Contributor SQL Injection in WPBulky <= 1.2.2 versions. | Aug 28, 2026 |
| CVE-2026-82220 | MEDIUM | 5.3 | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. | Aug 28, 2026 |
| CVE-2026-82181 | MEDIUM | 5.5 | Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history … | Aug 28, 2026 |
| CVE-2026-82112 | LOW | 3.5 | A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component … | Aug 28, 2026 |
| CVE-2026-82078 | UNKNOWN | — | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based … | Aug 28, 2026 |