Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42183
Total
3433
Critical
12465
High
12416
Medium
CVE ID Severity Score Description Published
CVE-2026-51737 MEDIUM 5.3 Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51736 CRITICAL 9.1 Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51735 HIGH 7.5 Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request … Aug 31, 2026
CVE-2026-51734 CRITICAL 9.8 Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST … Aug 31, 2026
CVE-2026-51733 UNKNOWN Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request … Aug 31, 2026
CVE-2026-51732 MEDIUM 5.3 Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request … Aug 31, 2026
CVE-2026-51731 CRITICAL 9.1 Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to … Aug 31, 2026
CVE-2026-14697 MEDIUM 6.5 net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and … Aug 31, 2026
CVE-2026-13732 HIGH 7.8 A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that … Aug 31, 2026
CVE-2026-83497 HIGH 8.8 Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to … Aug 31, 2026
CVE-2026-82821 MEDIUM 4.3 A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF … Aug 31, 2026
CVE-2026-82820 MEDIUM 4.3 A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The … Aug 31, 2026
CVE-2026-82818 MEDIUM 6.3 A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing … Aug 31, 2026
CVE-2026-72001 HIGH 8.1 Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the … Aug 31, 2026
CVE-2026-53553 HIGH 7.7 Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File … Aug 31, 2026
CVE-2026-53552 CRITICAL 9.6 Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row … Aug 31, 2026
CVE-2026-53508 UNKNOWN oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not … Aug 31, 2026
CVE-2026-53507 UNKNOWN oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff … Aug 31, 2026
CVE-2026-14696 MEDIUM 6.5 When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For frames that must … Aug 31, 2026
CVE-2026-14368 MEDIUM 5.4 The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if … Aug 31, 2026
CVE-2026-14367 LOW 3.1 The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The … Aug 31, 2026
CVE-2023-31308 LOW 3.3 A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read. Aug 31, 2026
CVE-2023-20511 MEDIUM 6.4 Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading … Aug 31, 2026
CVE-2026-82817 MEDIUM 6.3 A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator … Aug 31, 2026
CVE-2026-82816 MEDIUM 6.3 A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI … Aug 31, 2026