Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33951
Total
2635
Critical
10034
High
10234
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-30817 | UNKNOWN | — | An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious … | Apr 08, 2026 |
| CVE-2026-30816 | UNKNOWN | — | An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a … | Apr 08, 2026 |
| CVE-2026-30815 | UNKNOWN | — | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a … | Apr 08, 2026 |
| CVE-2026-30814 | UNKNOWN | — | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially … | Apr 08, 2026 |
| CVE-2026-2942 | CRITICAL | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all … | Apr 08, 2026 |
| CVE-2026-27806 | HIGH | 7.8 | Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password … | Apr 08, 2026 |
| CVE-2026-20709 | MEDIUM | 6.6 | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series … | Apr 08, 2026 |
| CVE-2026-0814 | MEDIUM | 4.3 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' … | Apr 08, 2026 |
| CVE-2026-0811 | MEDIUM | 5.4 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is … | Apr 08, 2026 |
| CVE-2025-50673 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50672 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50671 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability … | Apr 08, 2026 |
| CVE-2025-50670 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability … | Apr 08, 2026 |
| CVE-2025-50669 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50668 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50667 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50666 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this … | Apr 08, 2026 |
| CVE-2025-50665 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this … | Apr 08, 2026 |
| CVE-2025-50664 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability … | Apr 08, 2026 |
| CVE-2025-50663 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50662 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50661 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this … | Apr 08, 2026 |
| CVE-2025-50660 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50659 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50657 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint. | Apr 08, 2026 |