Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71935 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, … | Aug 24, 2026 |
| CVE-2026-71934 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, … | Aug 24, 2026 |
| CVE-2026-71933 | CRITICAL | 9.1 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger … | Aug 24, 2026 |
| CVE-2026-71932 | MEDIUM | 4.9 | Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A … | Aug 24, 2026 |
| CVE-2026-71931 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is … | Aug 24, 2026 |
| CVE-2026-71930 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71929 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71928 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71927 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71926 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and … | Aug 24, 2026 |
| CVE-2026-71925 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71924 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71923 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71922 | HIGH | 7.5 | Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass … | Aug 24, 2026 |
| CVE-2026-71921 | CRITICAL | 9.8 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field … | Aug 24, 2026 |
| CVE-2026-71920 | MEDIUM | 4.9 | Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or … | Aug 24, 2026 |
| CVE-2026-71919 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, … | Aug 24, 2026 |
| CVE-2026-71918 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, … | Aug 24, 2026 |
| CVE-2026-71917 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before … | Aug 24, 2026 |
| CVE-2026-71916 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as … | Aug 24, 2026 |
| CVE-2026-71915 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and … | Aug 24, 2026 |
| CVE-2026-71914 | CRITICAL | 9.8 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after … | Aug 24, 2026 |
| CVE-2026-71913 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is … | Aug 24, 2026 |
| CVE-2026-71912 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations … | Aug 24, 2026 |
| CVE-2026-71911 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations … | Aug 24, 2026 |