Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-58571 | HIGH | 8.8 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root … | Sep 01, 2026 |
| CVE-2026-51766 | HIGH | 7.5 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out … | Sep 01, 2026 |
| CVE-2026-51765 | UNKNOWN | — | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted … | Sep 01, 2026 |
| CVE-2026-51764 | UNKNOWN | — | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message … | Sep 01, 2026 |
| CVE-2026-51763 | UNKNOWN | — | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message … | Sep 01, 2026 |
| CVE-2026-51762 | UNKNOWN | — | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of … | Sep 01, 2026 |
| CVE-2026-51761 | MEDIUM | 5.3 | Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT … | Sep 01, 2026 |
| CVE-2026-51760 | UNKNOWN | — | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a … | Sep 01, 2026 |
| CVE-2026-51757 | UNKNOWN | — | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave … | Sep 01, 2026 |
| CVE-2026-51756 | MEDIUM | 5.9 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a … | Sep 01, 2026 |
| CVE-2026-51754 | UNKNOWN | — | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted … | Sep 01, 2026 |
| CVE-2026-51752 | MEDIUM | 5.3 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending … | Sep 01, 2026 |
| CVE-2026-51751 | UNKNOWN | — | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data … | Sep 01, 2026 |
| CVE-2026-51750 | UNKNOWN | — | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a … | Sep 01, 2026 |
| CVE-2026-51748 | MEDIUM | 5.9 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT … | Sep 01, 2026 |
| CVE-2026-19513 | HIGH | 8.1 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient … | Sep 01, 2026 |
| CVE-2026-18808 | CRITICAL | 9.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO … | Sep 01, 2026 |
| CVE-2026-18210 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company … | Sep 01, 2026 |
| CVE-2026-16675 | UNKNOWN | — | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows … | Sep 01, 2026 |
| CVE-2026-13348 | UNKNOWN | — | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an … | Sep 01, 2026 |
| CVE-2026-13337 | UNKNOWN | — | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is … | Sep 01, 2026 |
| CVE-2026-13336 | UNKNOWN | — | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands … | Sep 01, 2026 |
| CVE-2026-12663 | UNKNOWN | — | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary … | Sep 01, 2026 |
| CVE-2026-12661 | UNKNOWN | — | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, … | Sep 01, 2026 |
| CVE-2025-12768 | UNKNOWN | — | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the … | Sep 01, 2026 |