| CVE-2026-51765 | 9.8 | — | — | — | — | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthen | 4d ago |
| CVE-2026-51764 | 9.8 | — | — | — | — | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows una | 4d ago |
| CVE-2026-51763 | 9.8 | — | — | — | — | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 4d ago |
| CVE-2026-51762 | 9.8 | — | — | — | — | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 4d ago |
| CVE-2026-51760 | 9.8 | — | — | — | — | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 4d ago |
| CVE-2026-51757 | 9.8 | — | — | — | — | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 4d ago |
| CVE-2026-51754 | 9.8 | — | — | — | — | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic | 4d ago |
| CVE-2026-51751 | 9.8 | — | — | — | — | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 4d ago |
| CVE-2026-51750 | 9.8 | — | — | — | — | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 4d ago |
| CVE-2026-18808 | 9.8 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. | 4d ago |
| CVE-2026-18210 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Techno | 4d ago |
| CVE-2026-84143 | 9.8 | — | — | — | mozilla / firefox | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. | 4d ago |
| CVE-2026-84142 | 9.8 | — | — | — | mozilla / firefox | Internally found bugs present in Thunderbird 154. | 4d ago |
| CVE-2026-84141 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the Graphics: ImageLib component. | 4d ago |
| CVE-2026-84140 | 9.8 | — | — | — | mozilla / firefox | Site isolation issue in the DOM: Navigation component. | 4d ago |
| CVE-2026-84135 | 9.8 | — | — | — | mozilla / firefox mobile | Other issue in Firefox Focus for Android. | 4d ago |
| CVE-2026-84134 | 9.8 | — | — | — | mozilla / firefox | Other issue in the Profile Backup component. | 4d ago |
| CVE-2026-84133 | 9.8 | — | — | — | mozilla / firefox | Site isolation issue in the DOM: Push Subscriptions component. | 4d ago |
| CVE-2026-84129 | 9.8 | — | — | — | mozilla / firefox | Site isolation issue in the DOM: Navigation component. | 4d ago |
| CVE-2026-51747 | 9.8 | — | — | — | — | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 4d ago |
| CVE-2026-51744 | 9.8 | — | — | — | — | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent | 4d ago |
| CVE-2026-51741 | 9.8 | — | — | — | — | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic | 4d ago |
| CVE-2026-18765 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Sof | 4d ago |
| CVE-2026-18550 | 9.8 | — | — | — | — | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in | 4d ago |
| CVE-2026-75865 | 9.8 | — | — | — | — | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordP | 5d ago |
| CVE-2026-82226 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | 5d ago |
| CVE-2026-79408 | 9.8 | — | — | — | — | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the pa | 5d ago |
| CVE-2026-38577 | 9.8 | — | — | — | — | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root acce | 5d ago |
| CVE-2026-51740 | 9.8 | — | — | — | — | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a | 5d ago |
| CVE-2026-51738 | 9.8 | — | — | — | — | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51734 | 9.8 | — | — | — | — | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic | 5d ago |
| CVE-2026-51733 | 9.8 | — | — | — | — | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51728 | 9.8 | — | — | — | — | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51724 | 9.8 | — | — | — | — | Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 5d ago |
| CVE-2026-76133 | 9.8 | — | — | — | — | The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. | 5d ago |
| CVE-2026-73819 | 9.8 | — | — | — | — | The affected Ebyte product's vendor configuration utility permits access to administrative functions without verif | 5d ago |
| CVE-2026-51718 | 9.8 | — | — | — | — | Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51715 | 9.8 | — | — | — | — | Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic | 5d ago |
| CVE-2026-51709 | 9.8 | — | — | — | — | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51708 | 9.8 | — | — | — | — | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51705 | 9.8 | — | — | — | — | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51699 | 9.8 | — | — | — | — | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 5d ago |
| CVE-2026-51696 | 9.8 | — | — | — | — | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent | 5d ago |
| CVE-2026-51693 | 9.8 | — | — | — | — | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51691 | 9.8 | — | — | — | — | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 5d ago |
| CVE-2026-51686 | 9.8 | — | — | — | — | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 5d ago |
| CVE-2026-51684 | 9.8 | — | — | — | — | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51674 | 9.8 | — | — | — | — | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 5d ago |
| CVE-2026-51670 | 9.8 | — | — | — | — | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 5d ago |
| CVE-2026-82860 | 9.8 | — | — | — | — | @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the admin | 6d ago |
| CVE-2026-82859 | 9.8 | — | — | — | — | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac- | 6d ago |
| CVE-2026-82858 | 9.8 | — | — | — | — | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validat | 6d ago |
| CVE-2026-82857 | 9.8 | — | — | — | — | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy th | 6d ago |
| CVE-2026-82856 | 9.8 | — | — | — | — | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitH | 6d ago |
| CVE-2026-82855 | 9.8 | — | — | — | — | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deplo | 6d ago |
| CVE-2026-82854 | 9.8 | — | — | — | — | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. | 6d ago |
| CVE-2026-58574 | 9.8 | — | — | — | — | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. | 6d ago |
| CVE-2026-15980 | 9.8 | — | — | — | — | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, | 7d ago |
| CVE-2026-15369exploited | 9.8 | 0.40% | 1/3 | +2d | — | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in | 7d ago |
| CVE-2026-82460 | 9.8 | — | — | — | — | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown en | 7d ago |