Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
Showing 1,621 - 1,640 of 3,569 CVEs
CVE-2026-6138 CRITICAL - 9.8

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mac causes os command injection. The attack can be initiated remotely. The exploit ...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6132 CRITICAL - 9.8

A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. Remote exploitation of the attack is possible...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6131 CRITICAL - 9.8

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument command results in os command injection. The attack may be launched remo...

Published: Apr 12, 2026
Source: NVD
CVE-2019-25709 CRITICAL - 9.8

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the ...

Vendor: Davidtavarez
Product: CF Image Hosting Script
Published: Apr 12, 2026
Source: NVD
CVE-2026-6116 CRITICAL - 9.8

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument ip leads to os command injection. Remote exploitation of the attack is poss...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6115 CRITICAL - 9.8

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead to os command injection. The attack may be launched remotely. The exploit has be...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6114 CRITICAL - 9.8

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument proto results in os command injection. The attack may be initiated remo...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6113 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument ttyEnable leads to os command injection. The attack ca...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6112 CRITICAL - 9.8

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The expl...

Published: Apr 12, 2026
Source: NVD
CVE-2026-31845 CRITICAL - 9.3

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without prope...

Vendor: Rukovoditel
Product: Rukovoditel CRM
Published: Apr 11, 2026
Source: NVD
CVE-2026-34621 CRITICAL - 9.6

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this i...

Vendor: Adobe
Product: Acrobat Reader
Published: Apr 11, 2026
Source: NVD
CVE-2026-5059 CRITICAL - 9.8

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling ...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5058 CRITICAL - 9.8

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the a...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4149 CRITICAL - 10.0

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not required to exploit this vulnerability. The specific flaw exists within the han...

Vendor: sonos
Product: era_300_firmware
Published: Apr 11, 2026
Source: NVD
CVE-2026-40258 CRITICAL - 9.1

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. An authenticated user with owner-level privileges can craft a malicious ZIP file with directory-tra...

Vendor: pip
Product: gramps-webapi
Published: Apr 10, 2026
Source: GitHub
CVE-2026-40189 CRITICAL - 9.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload fi...

Vendor: patrickhener
Product: goshs
Published: Apr 10, 2026
Source: NVD

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.

Vendor: ajenti
Product: ajenti
Published: Apr 10, 2026
Source: NVD
CVE-2026-40175 CRITICAL - 10.0

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Comp...

Vendor: axios
Product: axios
Published: Apr 10, 2026
Source: NVD
CVE-2026-30232 CRITICAL - 9.6

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using request-promise without any IP a...

Vendor: chartbrew
Product: chartbrew
Published: Apr 10, 2026
Source: NVD
CVE-2026-33707 CRITICAL - 9.4

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the v...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 10, 2026
Source: NVD