2w ago
2026-08-31 16:18Z
CRIT

CVE-2026-51701 — Incorrect: access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51701

Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 16:18Z
CRIT

CVE-2026-51700 — Incorrect: access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51700

Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 16:18Z
CRIT

CVE-2026-51699 — Incorrect: access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51699

Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 16:18Z
CRIT

CVE-2026-51698 — Incorrect: access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51698

Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 16:18Z
CRIT

CVE-2026-51152 — Server: Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51152

Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not require authentication, enabling unauthenticated remote attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. validate_cert is set CVSSv3.1 9.1 (CRITICAL)

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 15:18Z
CRIT

CVE-2026-82970 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82970

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 15:17Z
HIGH

CVE-2026-66047 — ProfilePress: (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66047

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin installation and activation, achieving PHP code execution as the web-server user CVSSv3.1 8.1 (HIGH)

CWECWE 306CWECWE 330VNDProfilepressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-59111 — Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59111

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming URL parameters were passed to the compiled AppleScript wrapper using concatenation without sufficient sanitization. CVSSv3.1 9.3 (CRITICAL)

CWECWE 78TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51697 — Incorrect: access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51697

Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51696 — Incorrect: access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51696

Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51693 — Incorrect: access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51693

Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51692 — Incorrect: access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51692

Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51691 — Incorrect: access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51691

Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51690 — Incorrect: access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51690

Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51689 — Incorrect: access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51689

Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51687 — Incorrect: access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51687

Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51686 — Incorrect: access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51686

Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 15:17Z
CRIT

CVE-2026-51684 — Incorrect: access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51684

Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 15:13Z
INFO

v9.7.0-rc1

BloodHound releases·github.comCVE-2026-67213

BloodHound v9.7.0-rc1 release candidate published with 80+ commits including dependency updates, UI/UX improvements, accessibility enhancements, and security patches. Notable changes include Go version bumps (1.26.5→1.26.6), dompurify XSS CVE resolution, nanoid dependency update for CVE-2026-67213, and new features like multi-destination pathfinding and presigned artifact downloads.

SWBloodhoundVNDSpecteropsTYPTool
42
Edit Score
2w ago
2026-08-31 14:17Z
HIGH

CVE-2026-82217 — Eclipse: Because the path argument is influenced by model output, it can be steered through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82217

In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is in CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDEclipseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51681 — Incorrect: access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51681

Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51680 — Incorrect: access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51680

Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51679 — Incorrect: access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51679

Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51677 — Incorrect: access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51677

Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51676 — Incorrect: access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51676

Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score