VYPR

CVEs

37,811 total · page 33 of 757

  • CVE-2026-79408CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.02

    An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

  • CVE-2026-38577CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

  • CVE-2026-51740CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51736CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51734CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51731CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-53552CriAug 31, 2026
    risk 0.62cvss 9.6epss 0.00

    Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without…

  • CVE-2026-79748CriAug 31, 2026
    risk 0.57cvss 9.9epss 0.01

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP…

  • CVE-2026-51730CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51729CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51726CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51725CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51724CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51722CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51720CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-76133CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication…

  • CVE-2026-73819CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change…

  • CVE-2026-51718CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51717CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51711CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51710CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51709CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51708CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51705CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51701CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51152CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not…

  • CVE-2026-82970CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.

  • CVE-2026-59111CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized…

  • CVE-2026-51686CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51681CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51680CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51679CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51677CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51676CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51675CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51674CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51672CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51670CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51669CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-82695CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to…

  • CVE-2026-82694CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2026-82693CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The…

  • CVE-2026-82692CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.03

    A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate…

  • CVE-2026-82691CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command…

  • CVE-2026-82690CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.04

    A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out…

  • CVE-2026-82689CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.03

    A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command…

  • CVE-2026-82688CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.04

    A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name…

  • CVE-2026-49003CriAug 31, 2026
    risk 0.63cvss 9.6epss 0.02

    Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with…

  • CVE-2026-82874CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.00

    ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract…

  • CVE-2026-82872CriAug 31, 2026
    risk 0.52cvss 9.1epss 0.01

    ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId…