Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-9622 | UNKNOWN | — | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, … | Sep 01, 2026 |
| CVE-2026-9621 | UNKNOWN | — | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause … | Sep 01, 2026 |
| CVE-2026-84218 | HIGH | 8.1 | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to … | Sep 01, 2026 |
| CVE-2026-84109 | MEDIUM | 6.3 | A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing … | Sep 01, 2026 |
| CVE-2026-80047 | UNKNOWN | — | A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent … | Sep 01, 2026 |
| CVE-2026-79684 | HIGH | 8.8 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain … | Sep 01, 2026 |
| CVE-2026-58572 | HIGH | 8.8 | Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. | Sep 01, 2026 |
| CVE-2026-58571 | HIGH | 8.8 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root … | Sep 01, 2026 |
| CVE-2026-51766 | HIGH | 7.5 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out … | Sep 01, 2026 |
| CVE-2026-51765 | UNKNOWN | — | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted … | Sep 01, 2026 |
| CVE-2026-51764 | UNKNOWN | — | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message … | Sep 01, 2026 |
| CVE-2026-51763 | UNKNOWN | — | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message … | Sep 01, 2026 |
| CVE-2026-51762 | UNKNOWN | — | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of … | Sep 01, 2026 |
| CVE-2026-51761 | MEDIUM | 5.3 | Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT … | Sep 01, 2026 |
| CVE-2026-51760 | UNKNOWN | — | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a … | Sep 01, 2026 |
| CVE-2026-51757 | UNKNOWN | — | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave … | Sep 01, 2026 |
| CVE-2026-51756 | MEDIUM | 5.9 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a … | Sep 01, 2026 |
| CVE-2026-51754 | UNKNOWN | — | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted … | Sep 01, 2026 |
| CVE-2026-51752 | MEDIUM | 5.3 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending … | Sep 01, 2026 |
| CVE-2026-51751 | UNKNOWN | — | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data … | Sep 01, 2026 |
| CVE-2026-51750 | UNKNOWN | — | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a … | Sep 01, 2026 |
| CVE-2026-51748 | MEDIUM | 5.9 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT … | Sep 01, 2026 |
| CVE-2026-19513 | HIGH | 8.1 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient … | Sep 01, 2026 |
| CVE-2026-18808 | CRITICAL | 9.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO … | Sep 01, 2026 |
| CVE-2026-18210 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company … | Sep 01, 2026 |