Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-84117 — Privilege escalation in Firefox for Android

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

firefox firefox_mobile | Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-84061 — zhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injection

A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function _validate_sql_safety of the file openchatbi/text2sql/generate_sql.py. Performin…

openchatbi | Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-7877 — WP Recipe Maker Premium <= 10.5.0 - Authenticated (Contributor+) Stored Cross-Site Script…

The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insu…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.8 HIGH
CVE-2026-79683 — Dell PowerStore Protection Mechanism Failure Arbitrary File Write

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content …

Sep 01, 2026 Sep 30, 2026
Sep 01, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-58575 — Dell PowerStore Authentication Bypass Vulnerability

Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.

Sep 01, 2026 Sep 30, 2026
Sep 01, 2026
Sep 30, 2026
5.3 MEDIUM
CVE-2026-53682 — Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security d…

Sep 01, 2026 Sep 23, 2026
Sep 01, 2026
Sep 23, 2026
9.8 CRITICAL
CVE-2026-51747 — TOTOLINK T6 Access Control Bypass via MQTT Message Injection

Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a cr…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-51745 — TOTOLINK T6 Improper Access Control

Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message …

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51744 — TOTOLINK T6 Improper Access Control

Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-control…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.1 CRITICAL
CVE-2026-51743 — TOTOLINK Access Control Bypass

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT messag…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-51742 — TOTOLINK T6 Incorrect Access Control Vulnerability

Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bi…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51741 — TOTOLINK T6 Incorrect Access Control Vulnerability

Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin…

Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-19472 — Rockwell Automation ArmorStart® LT Denial Of Service

A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a lo…

armorstart_lt | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.9 MEDIUM
CVE-2026-19471 — Rockwell Automation ArmorStart® LT Stored Cross-site scripting

Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inje…

armorstart_lt | Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-18765 — SQL Injection in Teracity Sotware's Teracity E-OSB Platform

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 15055 Results