Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-71935 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, … Aug 24, 2026
CVE-2026-71934 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, … Aug 24, 2026
CVE-2026-71933 CRITICAL 9.1 Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger … Aug 24, 2026
CVE-2026-71932 MEDIUM 4.9 Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A … Aug 24, 2026
CVE-2026-71931 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is … Aug 24, 2026
CVE-2026-71930 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71929 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71928 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71927 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71926 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and … Aug 24, 2026
CVE-2026-71925 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71924 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71923 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password … Aug 24, 2026
CVE-2026-71922 HIGH 7.5 Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass … Aug 24, 2026
CVE-2026-71921 CRITICAL 9.8 Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field … Aug 24, 2026
CVE-2026-71920 MEDIUM 4.9 Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or … Aug 24, 2026
CVE-2026-71919 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, … Aug 24, 2026
CVE-2026-71918 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, … Aug 24, 2026
CVE-2026-71917 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before … Aug 24, 2026
CVE-2026-71916 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as … Aug 24, 2026
CVE-2026-71915 HIGH 7.2 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and … Aug 24, 2026
CVE-2026-71914 CRITICAL 9.8 Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after … Aug 24, 2026
CVE-2026-71913 HIGH 7.2 Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is … Aug 24, 2026
CVE-2026-71912 HIGH 7.2 Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations … Aug 24, 2026
CVE-2026-71911 HIGH 7.2 Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations … Aug 24, 2026