Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43400
Total
3514
Critical
12984
High
12813
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79745 | HIGH | 7.1 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, … | Aug 31, 2026 |
| CVE-2026-79744 | HIGH | 8.8 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, … | Aug 31, 2026 |
| CVE-2026-79743 | UNKNOWN | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, … | Aug 31, 2026 |
| CVE-2026-51730 | CRITICAL | 9.1 | Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51729 | CRITICAL | 9.1 | Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a … | Aug 31, 2026 |
| CVE-2026-51728 | UNKNOWN | — | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51727 | MEDIUM | 5.3 | Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a … | Aug 31, 2026 |
| CVE-2026-51726 | CRITICAL | 9.1 | Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51725 | CRITICAL | 9.1 | Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-19953 | MEDIUM | 6.5 | URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but … | Aug 31, 2026 |
| CVE-2026-82810 | LOW | 3.3 | A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service … | Aug 31, 2026 |
| CVE-2026-82809 | MEDIUM | 4.3 | A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component … | Aug 31, 2026 |
| CVE-2026-82808 | HIGH | 7.3 | A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the … | Aug 31, 2026 |
| CVE-2026-51724 | CRITICAL | 9.8 | Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51723 | UNKNOWN | — | Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51722 | CRITICAL | 9.1 | Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending … | Aug 31, 2026 |
| CVE-2026-51721 | CRITICAL | 9.1 | Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51720 | CRITICAL | 9.1 | Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-17615 | HIGH | 7.5 | A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted … | Aug 31, 2026 |
| CVE-2026-14366 | MEDIUM | 6.4 | The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the … | Aug 31, 2026 |
| CVE-2026-83492 | UNKNOWN | — | Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1. | Aug 31, 2026 |
| CVE-2026-82823 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-82814. Reason: This candidate is a reservation duplicate of CVE-2026-82814. Notes: All CVE … | Aug 31, 2026 |
| CVE-2026-82807 | HIGH | 8.8 | A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. … | Aug 31, 2026 |
| CVE-2026-82805 | MEDIUM | 4.3 | A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument … | Aug 31, 2026 |
| CVE-2026-82803 | MEDIUM | 5.3 | A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation … | Aug 31, 2026 |