2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51765 — Incorrect: access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51765

Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51764 — Incorrect: access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51764

Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51763 — Incorrect: access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51763

Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51762 — Incorrect: access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51762

Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51760 — Incorrect: access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51760

Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51757 — Incorrect: access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51757

Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51754 — Incorrect: access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51754

Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51751 — Incorrect: access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51751

Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51750 — Incorrect: access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51750

Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
HIGH

CVE-2026-19513 — Gravity: The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19513

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This makes it possible for unauthenticated attackers, when a public form contains a Fi CVSSv3.1 8.1 (HIGH)

CWECWE 434VNDGravityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-18808 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18808

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-18210 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18210

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84143 — Mozilla Firefox: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84143

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDMozillaVNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84142 — Mozilla Firefox: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84142

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDMozillaVNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84141 — Mozilla Firefox: Integer overflow in the Graphics: ImageLib component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84141

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84140 — Mozilla Firefox: Site isolation issue in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84140

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 346VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84135 — Mozilla Firefox_mobile: Other issue in Firefox Focus for Android.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84135

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84134 — Mozilla Firefox: Other issue in the Profile Backup component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84134

Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 200VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84133 — Mozilla Firefox: Site isolation issue in the DOM: Push Subscriptions component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84133

Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 346VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84131 — Privilege: escalation due to invalid pointer in the Graphics component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84131

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. CVSSv3.1 8.8 (HIGH)

CWECWE 763TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84129 — Site: isolation issue in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84129

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 346TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84128 — Privilege: escalation in the WebDriver BiDi component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84128

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84123 — Privilege: escalation due to use-after-free in the Graphics: WebGPU component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84123

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84121 — Sandbox: escape due to use-after-free in the DOM: Security component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84121

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84119 — Sandbox: escape due to use-after-free in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84119

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score