Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51715 | UNKNOWN | — | Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51714 | UNKNOWN | — | Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51713 | UNKNOWN | — | Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51712 | UNKNOWN | — | Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51711 | UNKNOWN | — | Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51710 | UNKNOWN | — | Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51709 | UNKNOWN | — | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51708 | UNKNOWN | — | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51706 | UNKNOWN | — | Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51705 | UNKNOWN | — | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51704 | UNKNOWN | — | Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51703 | UNKNOWN | — | Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51702 | UNKNOWN | — | Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51701 | UNKNOWN | — | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51700 | UNKNOWN | — | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51699 | UNKNOWN | — | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51698 | UNKNOWN | — | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51153 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208 through 20250803. When a task is run via /task/<taskid>/run, the handler renders task log … | Aug 31, 2026 |
| CVE-2026-51152 | UNKNOWN | — | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL … | Aug 31, 2026 |
| CVE-2026-21827 | LOW | 3.1 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by … | Aug 31, 2026 |
| CVE-2026-82970 | CRITICAL | 10.0 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. … | Aug 31, 2026 |
| CVE-2026-82801 | HIGH | 7.3 | A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. … | Aug 31, 2026 |
| CVE-2026-82703 | MEDIUM | 6.6 | A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component asp_setPing Endpoint. … | Aug 31, 2026 |
| CVE-2026-82702 | MEDIUM | 6.6 | A vulnerability was identified in Edimax BR-6214K 1.40. This affects the function system of the file www/wlanMP.asp of the component asp_WlanMP Endpoint. Such manipulation of … | Aug 31, 2026 |
| CVE-2026-82701 | HIGH | 7.3 | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component … | Aug 31, 2026 |