Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-71985 — MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected d…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71984 — MSI Radix AXE6600 v781521 Command Injection via urlfilter

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected devic…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19323 — azer react-analyzer-mcp analyze-projec index.ts generateProjectDocs path traversal

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index…

react-analyzer-mcp | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71983 — MSI Radix AXE6600 v781521 Command Injection via wps.cgi

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.1 MEDIUM
CVE-2026-71502 — Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Transm…

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthentic…

Remote | Cross-Site Scripting
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71958 — D-Link DWR-M961 Buffer Overflow via quicksetup.cgi

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly…

Remote | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71957 — D-Link DWR-M961 Buffer Overflow via app.cgi

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly lon…

Remote | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71956 — D-Link DWR-M961 Command Injection via app.cgi

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71955 — D-Link DWR-M961 Command Injection via /boafrm/formWsc

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject ar…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71954 — D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote a…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71953 — D-Link DWR-M961 Command Injection via /boafrm/formNtp

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can in…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71952 — D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote atta…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71951 — D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71950 — D-Link DWR-M961 Command Injection via /boafrm/formSmsManage

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71949 — D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71948 — D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71947 — D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A re…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71946 — D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote a…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71945 — D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remo…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71944 — D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remo…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
Showing 20 of 9708 Results