Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42239
Total
3441
Critical
12474
High
12431
Medium
CVE ID Severity Score Description Published
CVE-2026-82809 MEDIUM 4.3 A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component … Aug 31, 2026
CVE-2026-82808 HIGH 7.3 A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the … Aug 31, 2026
CVE-2026-51724 CRITICAL 9.8 Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request … Aug 31, 2026
CVE-2026-51723 UNKNOWN Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST … Aug 31, 2026
CVE-2026-51722 CRITICAL 9.1 Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending … Aug 31, 2026
CVE-2026-51721 CRITICAL 9.1 Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST … Aug 31, 2026
CVE-2026-51720 CRITICAL 9.1 Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request … Aug 31, 2026
CVE-2026-17615 HIGH 7.5 A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted … Aug 31, 2026
CVE-2026-14366 MEDIUM 6.4 The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the … Aug 31, 2026
CVE-2026-83492 UNKNOWN Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1. Aug 31, 2026
CVE-2026-82823 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-82814. Reason: This candidate is a reservation duplicate of CVE-2026-82814. Notes: All CVE … Aug 31, 2026
CVE-2026-82807 HIGH 8.8 A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. … Aug 31, 2026
CVE-2026-82805 MEDIUM 4.3 A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument … Aug 31, 2026
CVE-2026-82803 MEDIUM 5.3 A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation … Aug 31, 2026
CVE-2026-82802 MEDIUM 5.3 A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules … Aug 31, 2026
CVE-2026-77975 MEDIUM 6.5 The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain … Aug 31, 2026
CVE-2026-77966 HIGH 8.8 The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions … Aug 31, 2026
CVE-2026-76133 CRITICAL 9.8 The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, … Aug 31, 2026
CVE-2026-75133 HIGH 7.5 Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump … Aug 31, 2026
CVE-2026-75132 MEDIUM 6.5 WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with … Aug 31, 2026
CVE-2026-73819 CRITICAL 9.8 The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on … Aug 31, 2026
CVE-2026-51719 UNKNOWN Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request … Aug 31, 2026
CVE-2026-51718 UNKNOWN Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request … Aug 31, 2026
CVE-2026-51717 UNKNOWN Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST … Aug 31, 2026
CVE-2026-51716 UNKNOWN Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to … Aug 31, 2026