Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-9622 UNKNOWN A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, … Sep 01, 2026
CVE-2026-9621 UNKNOWN A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause … Sep 01, 2026
CVE-2026-84218 HIGH 8.1 A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to … Sep 01, 2026
CVE-2026-84109 MEDIUM 6.3 A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing … Sep 01, 2026
CVE-2026-80047 UNKNOWN A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent … Sep 01, 2026
CVE-2026-79684 HIGH 8.8 Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain … Sep 01, 2026
CVE-2026-58572 HIGH 8.8 Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. Sep 01, 2026
CVE-2026-58571 HIGH 8.8 Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root … Sep 01, 2026
CVE-2026-51766 HIGH 7.5 Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out … Sep 01, 2026
CVE-2026-51765 UNKNOWN Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted … Sep 01, 2026
CVE-2026-51764 UNKNOWN Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message … Sep 01, 2026
CVE-2026-51763 UNKNOWN Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message … Sep 01, 2026
CVE-2026-51762 UNKNOWN Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of … Sep 01, 2026
CVE-2026-51761 MEDIUM 5.3 Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT … Sep 01, 2026
CVE-2026-51760 UNKNOWN Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a … Sep 01, 2026
CVE-2026-51757 UNKNOWN Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave … Sep 01, 2026
CVE-2026-51756 MEDIUM 5.9 Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a … Sep 01, 2026
CVE-2026-51754 UNKNOWN Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted … Sep 01, 2026
CVE-2026-51752 MEDIUM 5.3 Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending … Sep 01, 2026
CVE-2026-51751 UNKNOWN Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data … Sep 01, 2026
CVE-2026-51750 UNKNOWN Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a … Sep 01, 2026
CVE-2026-51748 MEDIUM 5.9 Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT … Sep 01, 2026
CVE-2026-19513 HIGH 8.1 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient … Sep 01, 2026
CVE-2026-18808 CRITICAL 9.8 Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO … Sep 01, 2026
CVE-2026-18210 CRITICAL 9.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company … Sep 01, 2026