Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71918 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, … | Aug 24, 2026 |
| CVE-2026-71917 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before … | Aug 24, 2026 |
| CVE-2026-71916 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as … | Aug 24, 2026 |
| CVE-2026-71915 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and … | Aug 24, 2026 |
| CVE-2026-71914 | CRITICAL | 9.8 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after … | Aug 24, 2026 |
| CVE-2026-71913 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is … | Aug 24, 2026 |
| CVE-2026-71912 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations … | Aug 24, 2026 |
| CVE-2026-71911 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations … | Aug 24, 2026 |
| CVE-2026-71910 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and … | Aug 24, 2026 |
| CVE-2026-71909 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before … | Aug 24, 2026 |
| CVE-2026-71908 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip … | Aug 24, 2026 |
| CVE-2026-71907 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before … | Aug 24, 2026 |
| CVE-2026-71906 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask … | Aug 24, 2026 |
| CVE-2026-71905 | MEDIUM | 6.5 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET … | Aug 24, 2026 |
| CVE-2026-71904 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the … | Aug 24, 2026 |
| CVE-2026-34491 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. … | Aug 24, 2026 |
| CVE-2026-16348 | UNKNOWN | — | An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by … | Aug 24, 2026 |
| CVE-2026-13213 | MEDIUM | 5.3 | The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security … | Aug 24, 2026 |
| CVE-2026-78465 | HIGH | 7.0 | A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation … | Aug 24, 2026 |
| CVE-2026-78329 | UNKNOWN | — | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before … | Aug 24, 2026 |
| CVE-2026-77915 | CRITICAL | 9.8 | rConfig Core 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate … | Aug 24, 2026 |
| CVE-2026-77914 | MEDIUM | 6.5 | rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal … | Aug 24, 2026 |
| CVE-2026-76831 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |
| CVE-2026-76830 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |
| CVE-2026-76829 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |