VYPR

CVEs

382,981 total · page 309 of 7,660

  • CVE-2026-82703MedAug 31, 2026
    risk 0.43cvss 6.6epss 0.03

    A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component asp_setPing Endpoint. Performing a manipulation of the argument pingstr results in os command injection. The attack can be…

  • CVE-2026-82702MedAug 31, 2026
    risk 0.43cvss 6.6epss 0.03

    A vulnerability was identified in Edimax BR-6214K 1.40. This affects the function system of the file www/wlanMP.asp of the component asp_WlanMP Endpoint. Such manipulation of the argument ateFunc leads to os command injection. It is possible to launch the attack remotely. The…

  • CVE-2026-82701HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to…

  • CVE-2026-78422HigAug 31, 2026
    risk 0.40cvss —epss 0.00

    Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Because of this…

  • CVE-2026-66047HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.01

    ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the…

  • CVE-2026-63083Aug 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-59111CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized…

  • CVE-2026-51697Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51696Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51695Aug 31, 2026
    risk 0.00cvss —epss 0.00

    Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51694Aug 31, 2026
    risk 0.00cvss —epss 0.00

    Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51693Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51692Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51691Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51690Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51689Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51688Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51687Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51686CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51684Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51683MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-82700MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The…

  • CVE-2026-82699LowAug 31, 2026
    risk 0.18cvss 2.7epss 0.00

    A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component Password Handler. Executing a manipulation of the argument Password can lead to cleartext storage of…

  • CVE-2026-82698MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible.…

  • CVE-2026-82697LowAug 31, 2026
    risk 0.24cvss 3.7epss 0.00

    A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without 'httponly' flag. The attack may be launched remotely. A…

  • CVE-2026-82217HigAug 31, 2026
    risk 0.50cvss 8.8epss 0.01

    In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path…

  • CVE-2026-78079MedAug 31, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.

  • CVE-2026-78078HigAug 31, 2026
    risk 0.58cvss —epss 0.00

    Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict…

  • CVE-2026-78077HigAug 31, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual…

  • CVE-2026-78076MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or…

  • CVE-2026-78075MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image…

  • CVE-2026-78074HigAug 31, 2026
    risk 0.57cvss —epss 0.01

    Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are…

  • CVE-2026-76986MedAug 31, 2026
    risk 0.40cvss 6.1epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — into the…

  • CVE-2026-76985MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the…

  • CVE-2026-76763HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can…

  • CVE-2026-51681CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51680CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51679CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51678MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51677CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51676CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51675CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51674CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51673HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51672CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51671HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51670CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51669CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51668HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-19702HigAug 31, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.