Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42239
Total
3441
Critical
12474
High
12431
Medium
CVE ID Severity Score Description Published
CVE-2026-51715 UNKNOWN Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request … Aug 31, 2026
CVE-2026-51714 UNKNOWN Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51713 UNKNOWN Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request … Aug 31, 2026
CVE-2026-51712 UNKNOWN Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request … Aug 31, 2026
CVE-2026-51711 UNKNOWN Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST … Aug 31, 2026
CVE-2026-51710 UNKNOWN Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51709 UNKNOWN Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request … Aug 31, 2026
CVE-2026-51708 UNKNOWN Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51706 UNKNOWN Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51705 UNKNOWN Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51704 UNKNOWN Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51703 UNKNOWN Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST … Aug 31, 2026
CVE-2026-51702 UNKNOWN Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51701 UNKNOWN Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request … Aug 31, 2026
CVE-2026-51700 UNKNOWN Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51699 UNKNOWN Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request … Aug 31, 2026
CVE-2026-51698 UNKNOWN Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to … Aug 31, 2026
CVE-2026-51153 UNKNOWN Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208 through 20250803. When a task is run via /task/<taskid>/run, the handler renders task log … Aug 31, 2026
CVE-2026-51152 UNKNOWN Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL … Aug 31, 2026
CVE-2026-21827 LOW 3.1 HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by … Aug 31, 2026
CVE-2026-82970 CRITICAL 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. … Aug 31, 2026
CVE-2026-82801 HIGH 7.3 A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. … Aug 31, 2026
CVE-2026-82703 MEDIUM 6.6 A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component asp_setPing Endpoint. … Aug 31, 2026
CVE-2026-82702 MEDIUM 6.6 A vulnerability was identified in Edimax BR-6214K 1.40. This affects the function system of the file www/wlanMP.asp of the component asp_WlanMP Endpoint. Such manipulation of … Aug 31, 2026
CVE-2026-82701 HIGH 7.3 A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component … Aug 31, 2026