Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2026-71943 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71942 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a … Aug 24, 2026
CVE-2026-71941 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a … Aug 24, 2026
CVE-2026-71940 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into … Aug 24, 2026
CVE-2026-71939 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into … Aug 24, 2026
CVE-2026-71938 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into … Aug 24, 2026
CVE-2026-71937 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, … Aug 24, 2026
CVE-2026-71936 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into … Aug 24, 2026
CVE-2026-71935 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, … Aug 24, 2026
CVE-2026-71934 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, … Aug 24, 2026
CVE-2026-71933 CRITICAL 9.1 Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger … Aug 24, 2026
CVE-2026-71932 MEDIUM 4.9 Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A … Aug 24, 2026
CVE-2026-71931 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is … Aug 24, 2026
CVE-2026-71930 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71929 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71928 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71927 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71926 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and … Aug 24, 2026
CVE-2026-71925 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71924 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71923 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71922 HIGH 7.5 Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass … Aug 24, 2026
CVE-2026-71921 CRITICAL 9.8 Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field … Aug 24, 2026
CVE-2026-71920 MEDIUM 4.9 Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or … Aug 24, 2026
CVE-2026-71919 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, … Aug 24, 2026