Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71943 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71942 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a … | Aug 24, 2026 |
| CVE-2026-71941 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a … | Aug 24, 2026 |
| CVE-2026-71940 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into … | Aug 24, 2026 |
| CVE-2026-71939 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into … | Aug 24, 2026 |
| CVE-2026-71938 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into … | Aug 24, 2026 |
| CVE-2026-71937 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, … | Aug 24, 2026 |
| CVE-2026-71936 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into … | Aug 24, 2026 |
| CVE-2026-71935 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, … | Aug 24, 2026 |
| CVE-2026-71934 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, … | Aug 24, 2026 |
| CVE-2026-71933 | CRITICAL | 9.1 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger … | Aug 24, 2026 |
| CVE-2026-71932 | MEDIUM | 4.9 | Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A … | Aug 24, 2026 |
| CVE-2026-71931 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is … | Aug 24, 2026 |
| CVE-2026-71930 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71929 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71928 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71927 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71926 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and … | Aug 24, 2026 |
| CVE-2026-71925 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71924 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71923 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71922 | HIGH | 7.5 | Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass … | Aug 24, 2026 |
| CVE-2026-71921 | CRITICAL | 9.8 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field … | Aug 24, 2026 |
| CVE-2026-71920 | MEDIUM | 4.9 | Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or … | Aug 24, 2026 |
| CVE-2026-71919 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, … | Aug 24, 2026 |