VYPR

CVEs

382,819 total · page 299 of 7,657

  • CVE-2026-51760CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51757CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51756MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51754CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51752MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51751CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51750CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51748MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-19513HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.01

    The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be…

  • CVE-2026-18808CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.

  • CVE-2026-18210CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before…

  • CVE-2026-16675HigSep 1, 2026
    risk 0.55cvss —epss 0.00

    A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated…

  • CVE-2026-13348MedSep 1, 2026
    risk 0.45cvss —epss 0.00

    CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

  • CVE-2026-13337MedSep 1, 2026
    risk 0.33cvss —epss 0.00

    CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.

  • CVE-2026-13336HigSep 1, 2026
    risk 0.47cvss —epss 0.01

    CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.

  • CVE-2026-12663HigSep 1, 2026
    risk 0.45cvss —epss 0.00

    A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of…

  • CVE-2026-12661MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become…

  • CVE-2025-12768HigSep 1, 2026
    risk 0.56cvss —epss 0.00

    A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.

  • CVE-2024-14047HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.00

    A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated…

  • CVE-2024-10085HigSep 1, 2026
    risk 0.53cvss —epss 0.00

    CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.

  • CVE-2026-84235HigSep 1, 2026
    risk 0.57cvss —epss 0.00

    A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

  • CVE-2026-84149CriSep 1, 2026
    risk 0.60cvss —epss 0.01

    This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and…

  • CVE-2026-84148CriSep 1, 2026
    risk 0.60cvss —epss 0.01

    This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information…

  • CVE-2026-84147CriSep 1, 2026
    risk 0.65cvss —epss 0.01

    This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the…

  • CVE-2026-84145HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-84144HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in…

  • CVE-2026-84143CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-84142CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and…

  • CVE-2026-84141CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84140CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84139MedSep 1, 2026
    risk 0.40cvss 6.1epss 0.00

    Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84138MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84137MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84136MedSep 1, 2026
    risk 0.40cvss 6.1epss 0.00

    Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84135CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

  • CVE-2026-84134CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84133CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84132HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84131HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84130HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84129CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84128HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84127MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

  • CVE-2026-84126MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84125MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84124MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84123HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84122MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84121CriSep 1, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84120MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.