CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71928
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71927
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71926
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and …

Aug 24, 2026
CVE-2026-71925
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71924
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71923
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71922
7.5 HIGH

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass …

Aug 24, 2026
CVE-2026-71921
9.8 CRITICAL

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field …

Aug 24, 2026
CVE-2026-71920
4.9 MEDIUM

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or …

Aug 24, 2026
CVE-2026-71919
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, …

Aug 24, 2026
CVE-2026-71918
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, …

Aug 24, 2026
CVE-2026-71917
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before …

Aug 24, 2026
CVE-2026-71916
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as …

Aug 24, 2026
CVE-2026-71915
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and …

Aug 24, 2026
CVE-2026-71914
9.8 CRITICAL

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after …

Aug 24, 2026
CVE-2026-71913
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is …

Aug 24, 2026
CVE-2026-71912
7.2 HIGH

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations …

Aug 24, 2026
CVE-2026-71911
7.2 HIGH

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations …

Aug 24, 2026
CVE-2026-71910
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and …

Aug 24, 2026
CVE-2026-71909
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before …

Aug 24, 2026
CVE-2026-71908
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip …

Aug 24, 2026
CVE-2026-71907
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before …

Aug 24, 2026
CVE-2026-71906
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask …

Aug 24, 2026
CVE-2026-71905
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and …

Aug 24, 2026
CVE-2026-71904
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the …

Aug 24, 2026
CVE-2026-34491

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. …

Aug 24, 2026
CVE-2026-16348

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by …

Aug 24, 2026
CVE-2026-13213
5.3 MEDIUM

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security …

Aug 24, 2026
CVE-2026-78465
7.0 HIGH

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation …

Aug 24, 2026
CVE-2026-78329
9.8 CRITICAL

Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before …

Aug 24, 2026
CVE-2026-77915
9.8 CRITICAL

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate …

Aug 24, 2026
CVE-2026-77914
6.5 MEDIUM

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal …

Aug 24, 2026
CVE-2026-76831

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 24, 2026
CVE-2026-76830

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 24, 2026
CVE-2026-76829

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 24, 2026
CVE-2026-75099
5.3 MEDIUM

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, …

Aug 24, 2026
CVE-2026-71300
9.8 CRITICAL

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 …

Aug 24, 2026
CVE-2026-66908
7.5 HIGH

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can …

Aug 24, 2026
CVE-2026-66907
7.5 HIGH

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 …

Aug 24, 2026
CVE-2026-66906
9.1 CRITICAL

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from …

Aug 24, 2026
CVE-2026-63621
5.3 MEDIUM

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer …

Aug 24, 2026
CVE-2026-60093
5.5 MEDIUM

Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 …

Aug 24, 2026
CVE-2026-59230
6.5 MEDIUM

Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The …

Aug 24, 2026
CVE-2026-19685
7.1 HIGH

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user …

Aug 24, 2026
CVE-2026-18349

Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4.

Aug 24, 2026
CVE-2026-15469

The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. A shared …

Aug 24, 2026
CVE-2025-36940
8.8 HIGH

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

Aug 24, 2026
CVE-2025-36939

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a …

Aug 24, 2026
CVE-2026-78416

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. …

Aug 24, 2026
CVE-2026-76071
9.8 CRITICAL

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.