| CVE-2026-84479 | 9.1 | — | — | — | — | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-s | 4d ago |
| CVE-2026-84639 | 9.1 | — | — | — | mozilla / thunderbird | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. | 4d ago |
| CVE-2026-18931 | 9.1 | — | — | — | — | Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. | 4d ago |
| CVE-2026-51743 | 9.1 | — | — | — | — | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 4d ago |
| CVE-2026-51736 | 9.1 | — | — | — | — | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a | 5d ago |
| CVE-2026-51731 | 9.1 | — | — | — | — | Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at | 5d ago |
| CVE-2026-51730 | 9.1 | — | — | — | — | Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51729 | 9.1 | — | — | — | — | Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 5d ago |
| CVE-2026-51726 | 9.1 | — | — | — | — | Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 5d ago |
| CVE-2026-51725 | 9.1 | — | — | — | — | Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51723 | 9.1 | — | — | — | — | Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51722 | 9.1 | — | — | — | — | Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51721 | 9.1 | — | — | — | — | Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at | 5d ago |
| CVE-2026-51720 | 9.1 | — | — | — | — | Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthen | 5d ago |
| CVE-2026-51717 | 9.1 | — | — | — | — | Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51713 | 9.1 | — | — | — | — | Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 5d ago |
| CVE-2026-51711 | 9.1 | — | — | — | — | Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51710 | 9.1 | — | — | — | — | Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 5d ago |
| CVE-2026-51701 | 9.1 | — | — | — | — | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic | 5d ago |
| CVE-2026-51700 | 9.1 | — | — | — | — | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51698 | 9.1 | — | — | — | — | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentic | 5d ago |
| CVE-2026-51152 | 9.1 | — | — | — | — | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. | 5d ago |
| CVE-2026-51697 | 9.1 | — | — | — | — | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at | 5d ago |
| CVE-2026-51692 | 9.1 | — | — | — | — | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 5d ago |
| CVE-2026-51690 | 9.1 | — | — | — | — | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 5d ago |
| CVE-2026-51689 | 9.1 | — | — | — | — | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51687 | 9.1 | — | — | — | — | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51681 | 9.1 | — | — | — | — | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51680 | 9.1 | — | — | — | — | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 5d ago |
| CVE-2026-51679 | 9.1 | — | — | — | — | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 5d ago |
| CVE-2026-51677 | 9.1 | — | — | — | — | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at | 5d ago |
| CVE-2026-51676 | 9.1 | — | — | — | — | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti | 5d ago |
| CVE-2026-51675 | 9.1 | — | — | — | — | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a | 5d ago |
| CVE-2026-51672 | 9.1 | — | — | — | — | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 5d ago |
| CVE-2026-51669 | 9.1 | — | — | — | — | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at | 5d ago |
| CVE-2026-82691 | 9.1 | — | — | — | — | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. | 5d ago |
| CVE-2026-82690 | 9.1 | — | — | — | — | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. | 5d ago |
| CVE-2026-82688 | 9.1 | — | — | — | — | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. | 5d ago |
| CVE-2026-82872 | 9.1 | — | — | — | — | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace | 6d ago |
| CVE-2026-82539 | 9.1 | — | — | — | — | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. | 6d ago |
| CVE-2026-82454 | 9.1 | — | — | — | — | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-i | 7d ago |
| CVE-2026-16947 | 9.1 | — | — | — | — | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied | 8d ago |
| CVE-2026-51661 | 9.1 | — | — | — | — | Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent | 8d ago |
| CVE-2026-3627 | 9.1 | — | — | — | ibm / concert | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. | 8d ago |
| CVE-2026-55511 | 9.1 | — | — | — | — | Yamcs is a mission control framework. | 8d ago |
| CVE-2026-55248 | 9.1 | — | — | — | — | plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. | 8d ago |
| CVE-2026-55247 | 9.1 | — | — | — | — | plone.app.event provides the event content type for Plone. | 8d ago |
| CVE-2026-51660 | 9.1 | — | — | — | — | Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthen | 8d ago |
| CVE-2026-51657 | 9.1 | — | — | — | — | Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 8d ago |
| CVE-2026-51649 | 9.1 | — | — | — | — | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 8d ago |
| CVE-2026-51646 | 9.1 | — | — | — | — | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 8d ago |
| CVE-2026-51643 | 9.1 | — | — | — | — | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 8d ago |
| CVE-2026-51636 | 9.1 | — | — | — | — | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat | 8d ago |
| CVE-2026-51628 | 9.1 | — | — | — | — | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe | 8d ago |
| CVE-2026-51626 | 9.1 | — | — | — | — | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated | 8d ago |
| CVE-2026-51622 | 9.1 | — | — | — | — | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att | 8d ago |
| CVE-2026-82078zero day | 9.1 | 1.7% | 3/3 | 1d before | papercut / papercut mf | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and Paper | 8d ago |
| CVE-2026-82244 | 9.1 | — | — | — | — | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authe | 8d ago |
| CVE-2026-42007 | 9.1 | — | — | — | — | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after | 8d ago |
| CVE-2026-80670 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() i | 9d ago |