VYPR

CVEs

382,973 total · page 308 of 7,660

  • CVE-2026-51721Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51720CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-17615HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts…

  • CVE-2026-14366MedAug 31, 2026
    risk 0.35cvss 6.4epss 0.00

    The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking stack; the driver only borrows it to copy the frame bytes into a…

  • CVE-2026-83492MedAug 31, 2026
    risk 0.45cvss —epss 0.00

    Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.

  • CVE-2026-82823Aug 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-82814. Reason: This candidate is a reservation duplicate of CVE-2026-82814. Notes: All CVE users should reference CVE-2026-82814 instead of this candidate. All references and descriptions in…

  • CVE-2026-82807HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit…

  • CVE-2026-82805MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument classDef/style results in cross site scripting. The attack may be launched remotely. The exploit has been…

  • CVE-2026-82803MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation of the argument valuestring leads to null pointer dereference. The…

  • CVE-2026-82802MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd…

  • CVE-2026-77975MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use…

  • CVE-2026-77966HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity,…

  • CVE-2026-76133CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication…

  • CVE-2026-75133HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication.…

  • CVE-2026-75132MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL expressions into the SQL query constructed by…

  • CVE-2026-73819CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change…

  • CVE-2026-51719HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51718CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51717CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51716HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51715Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51714MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51713Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51712MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51711CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51710CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51709CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51708CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51706MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51705CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51704MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51703MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51702MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51701CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51700Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51699Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51698Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51153MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208 through 20250803. When a task is run via /task//run, the handler renders task log content (logtmp) into the HTML response using Python % string formatting without HTML…

  • CVE-2026-51152CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not…

  • CVE-2026-21827LowAug 31, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

  • CVE-2026-82970CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.

  • CVE-2026-82801HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack…

  • CVE-2026-82703MedAug 31, 2026
    risk 0.43cvss 6.6epss 0.03

    A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component asp_setPing Endpoint. Performing a manipulation of the argument pingstr results in os command injection. The attack can be…

  • CVE-2026-82702MedAug 31, 2026
    risk 0.43cvss 6.6epss 0.03

    A vulnerability was identified in Edimax BR-6214K 1.40. This affects the function system of the file www/wlanMP.asp of the component asp_WlanMP Endpoint. Such manipulation of the argument ateFunc leads to os command injection. It is possible to launch the attack remotely. The…

  • CVE-2026-82701HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to…

  • CVE-2026-78422HigAug 31, 2026
    risk 0.40cvss —epss 0.00

    Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Because of this…

  • CVE-2026-66047HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.01

    ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the…

  • CVE-2026-63083Aug 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-59111CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized…

  • CVE-2026-51697Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.