CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-51647
7.5 HIGH

Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a …

Aug 28, 2026
CVE-2026-51644
7.5 HIGH

Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a …

Aug 28, 2026
CVE-2026-51642
7.5 HIGH

Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request …

Aug 28, 2026
CVE-2026-51641
7.5 HIGH

Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a …

Aug 28, 2026
CVE-2026-51627
7.5 HIGH

Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted …

Aug 28, 2026
CVE-2026-51625
7.5 HIGH

Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via …

Aug 28, 2026
CVE-2026-51624
7.5 HIGH

Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST …

Aug 28, 2026
CVE-2026-51623
7.5 HIGH

Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending …

Aug 28, 2026
CVE-2026-51621
7.5 HIGH

Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST …

Aug 28, 2026
CVE-2026-51620
7.5 HIGH

Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a …

Aug 28, 2026
CVE-2026-51619
7.5 HIGH

Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request …

Aug 28, 2026
CVE-2026-51618
7.5 HIGH

Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a …

Aug 28, 2026
CVE-2026-51617
7.5 HIGH

Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial …

Aug 28, 2026
CVE-2026-51616
7.5 HIGH

Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a …

Aug 28, 2026
CVE-2026-51615
7.5 HIGH

Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a …

Aug 28, 2026
CVE-2026-82227
8.5 HIGH

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

Aug 28, 2026
CVE-2026-81767
7.5 HIGH

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Aug 28, 2026
CVE-2026-81760
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.

Aug 28, 2026
CVE-2026-81757
7.2 HIGH

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

Aug 28, 2026
CVE-2026-81285
7.5 HIGH

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

Aug 28, 2026
CVE-2026-81020
7.4 HIGH

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a …

Aug 28, 2026
CVE-2026-81019
7.4 HIGH

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a …

Aug 28, 2026
CVE-2026-6176
7.2 HIGH

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and …

Aug 28, 2026
CVE-2026-5934
7.2 HIGH

The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input …

Aug 28, 2026
CVE-2026-56854
7.5 HIGH

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for …

Aug 28, 2026
CVE-2026-50979
8.1 HIGH

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the …

Aug 28, 2026
CVE-2026-38638
7.5 HIGH

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-38636
7.5 HIGH

An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-37736
7.5 HIGH

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-37237
7.5 HIGH

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py …

Aug 28, 2026
CVE-2026-82261
7.5 HIGH

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send …

Aug 28, 2026
CVE-2026-82260
7.5 HIGH

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form …

Aug 28, 2026
CVE-2026-82259
7.5 HIGH

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions …

Aug 28, 2026
CVE-2026-82254
7.5 HIGH

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data …

Aug 28, 2026
CVE-2026-82253
7.5 HIGH

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the …

Aug 28, 2026
CVE-2026-82252
7.5 HIGH

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious …

Aug 28, 2026
CVE-2026-82251
7.5 HIGH

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names …

Aug 28, 2026
CVE-2026-82247
7.5 HIGH

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, …

Aug 28, 2026
CVE-2026-82246
7.1 HIGH

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers …

Aug 28, 2026
CVE-2026-82245
8.1 HIGH

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers …

Aug 28, 2026
CVE-2026-82243
7.6 HIGH

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF …

Aug 28, 2026
CVE-2026-82242
7.7 HIGH

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens …

Aug 28, 2026
CVE-2026-82241
7.1 HIGH

Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query …

Aug 28, 2026
CVE-2026-82240
8.1 HIGH

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant …

Aug 28, 2026
CVE-2026-82239
8.1 HIGH

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows …

Aug 28, 2026
CVE-2026-82234
8.2 HIGH

SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time …

Aug 28, 2026
CVE-2026-73208
7.4 HIGH

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, …

Aug 28, 2026
CVE-2026-42391
7.5 HIGH

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage …

Aug 28, 2026
CVE-2026-40018
7.4 HIGH

None None None No publicly available exploits are known.

Aug 28, 2026
CVE-2026-33605
7.5 HIGH

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.