Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42683
Total
3463
Critical
12701
High
12563
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51630 | UNKNOWN | — | Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending … | Aug 28, 2026 |
| CVE-2026-51629 | UNKNOWN | — | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51628 | UNKNOWN | — | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a … | Aug 28, 2026 |
| CVE-2026-51627 | UNKNOWN | — | Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51626 | UNKNOWN | — | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a … | Aug 28, 2026 |
| CVE-2026-51625 | UNKNOWN | — | Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via … | Aug 28, 2026 |
| CVE-2026-51624 | UNKNOWN | — | Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51623 | UNKNOWN | — | Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending … | Aug 28, 2026 |
| CVE-2026-51622 | UNKNOWN | — | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51621 | UNKNOWN | — | Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51620 | UNKNOWN | — | Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51619 | UNKNOWN | — | Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51618 | UNKNOWN | — | Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51617 | UNKNOWN | — | Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial … | Aug 28, 2026 |
| CVE-2026-51616 | UNKNOWN | — | Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51615 | UNKNOWN | — | Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a … | Aug 28, 2026 |
| CVE-2026-51614 | UNKNOWN | — | Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a … | Aug 28, 2026 |
| CVE-2026-51613 | UNKNOWN | — | Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51611 | UNKNOWN | — | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. | Aug 28, 2026 |
| CVE-2026-51610 | UNKNOWN | — | Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51376 | UNKNOWN | — | An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh … | Aug 28, 2026 |
| CVE-2026-50980 | UNKNOWN | — | Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via … | Aug 28, 2026 |
| CVE-2026-39071 | UNKNOWN | — | WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) … | Aug 28, 2026 |
| CVE-2026-39070 | UNKNOWN | — | WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit … | Aug 28, 2026 |
| CVE-2026-82330 | MEDIUM | 6.1 | A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly … | Aug 28, 2026 |