Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-58572 — Dell PowerStore Code Injection Vulnerability

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.

Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-58571 — Dell PowerStore OS Command Injection Vulnerability

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root priv…

Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
7.5 HIGH
CVE-2026-51766 — TOTOLINK T6 Improper Access Control

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mes…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51765 — TOTOLINK T6 Improper Access Control

Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQ…

Remote | Authentication
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
9.8 CRITICAL
CVE-2026-51764 — TOTOLINK T6 Access Control Bypass via MQTT Message

Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-51763 — TOTOLINK T6 Improper Access Control

Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message…

Remote | Authentication
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-51762 — TOTOLINK T6 Mesh Information Access Control Bypass

Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of m…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-51761 — TOTOLINK T6 Incorrect Access Control Vulnerability

Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the c…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51760 — TOTOLINK T6 Improper Access Control

Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending …

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-51757 — TOTOLINK T6 Improper Access Control

Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via s…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
5.9 MEDIUM
CVE-2026-51756 — TOTOLINK T6 Improper Access Control

Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a cra…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51754 — TOTOLINK T6 Access Control Bypass

Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT m…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-51752 — TOTOLINK T6 Improper Access Control

Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via send…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51751 — TOTOLINK T6 Improper Access Control Vulnerability

Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and re…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-51750 — TOTOLINK Mesh Router Access Control Bypass

Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQT…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
5.9 MEDIUM
CVE-2026-51748 — TOTOLINK T6 Incorrect Access Control Vulnerability

Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQ…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.1 HIGH
CVE-2026-19513 — Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confu…

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in t…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-18808 — Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan I…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-18210 — SQL Injection in TRtek Technological Products's Store

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Produc…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.5 HIGH
CVE-2026-16675 — Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation

A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYST…

Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 15055 Results