Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42275
Total
3446
Critical
12492
High
12441
Medium
CVE ID Severity Score Description Published
CVE-2026-51622 UNKNOWN Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request … Aug 28, 2026
CVE-2026-51621 UNKNOWN Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST … Aug 28, 2026
CVE-2026-51620 UNKNOWN Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a … Aug 28, 2026
CVE-2026-51619 UNKNOWN Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request … Aug 28, 2026
CVE-2026-51618 UNKNOWN Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a … Aug 28, 2026
CVE-2026-51617 UNKNOWN Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial … Aug 28, 2026
CVE-2026-51616 UNKNOWN Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a … Aug 28, 2026
CVE-2026-51615 UNKNOWN Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a … Aug 28, 2026
CVE-2026-51614 UNKNOWN Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a … Aug 28, 2026
CVE-2026-51613 UNKNOWN Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request … Aug 28, 2026
CVE-2026-51611 UNKNOWN Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. Aug 28, 2026
CVE-2026-51610 UNKNOWN Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST … Aug 28, 2026
CVE-2026-51376 UNKNOWN An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh … Aug 28, 2026
CVE-2026-50980 UNKNOWN Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via … Aug 28, 2026
CVE-2026-39071 UNKNOWN WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) … Aug 28, 2026
CVE-2026-39070 UNKNOWN WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit … Aug 28, 2026
CVE-2026-82330 MEDIUM 6.1 A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly … Aug 28, 2026
CVE-2026-82328 MEDIUM 6.1 A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the … Aug 28, 2026
CVE-2026-82327 MEDIUM 5.5 A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache … Aug 28, 2026
CVE-2026-82324 MEDIUM 6.1 A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate … Aug 28, 2026
CVE-2026-82227 HIGH 8.5 Contributor SQL Injection in WPBulky <= 1.2.2 versions. Aug 28, 2026
CVE-2026-82220 MEDIUM 5.3 Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. Aug 28, 2026
CVE-2026-82181 MEDIUM 5.5 Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history … Aug 28, 2026
CVE-2026-82112 LOW 3.5 A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component … Aug 28, 2026
CVE-2026-82078 UNKNOWN An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based … Aug 28, 2026