Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71993 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71992 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71991 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to … | Aug 09, 2026 |
| CVE-2026-71990 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to … | Aug 09, 2026 |
| CVE-2026-71989 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71988 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71987 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71986 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71985 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-71984 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on … | Aug 09, 2026 |
| CVE-2026-19323 | MEDIUM | 5.3 | A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of … | Aug 09, 2026 |
| CVE-2026-71983 | CRITICAL | 9.8 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by … | Aug 08, 2026 |
| CVE-2026-11612 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 08, 2026 |
| CVE-2026-71502 | UNKNOWN | — | CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create … | Aug 08, 2026 |
| CVE-2026-71958 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write … | Aug 08, 2026 |
| CVE-2026-71957 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write … | Aug 08, 2026 |
| CVE-2026-71956 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject … | Aug 08, 2026 |
| CVE-2026-71955 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject … | Aug 08, 2026 |
| CVE-2026-71954 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71953 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71952 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71951 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71950 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71949 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71948 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can … | Aug 08, 2026 |