CVE Records
Page 3 of 19. 1892 curated CVE records with CVSS, EPSS, and CISA KEV status.
Records
1892 total| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-4228 | LB-LINK BL-WR9000 set_wifi sub_458754 command injection | LB-LINK | 6.5 | 8.9% | 2026-03-16 | |
| CVE-2026-4210 | D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-4209 | D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-4207 | D-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-4206 | D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-4205 | D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-4204 | D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-4203 | D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection | D-Link | 6.5 | 6.1% | 2026-03-16 | |
| CVE-2026-4197 | D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection | D-Link | 6.5 | 23.7% | 2026-03-15 | |
| CVE-2026-4196 | D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection | D-Link | 6.5 | 5.8% | 2026-03-15 | |
| CVE-2026-4195 | D-Link DNS-1550-04 wizard_mgr.cgi command injection | D-Link | 6.5 | 5.5% | 2026-03-15 | |
| CVE-2026-3891 | Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload | linknacional | 9.8 | 29.7% | 2026-03-13 | |
| CVE-2026-3910 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | 8.8 | 1.0% | KEV | 2026-03-12 | |
| CVE-2026-3909 | Google Skia Out-of-Bounds Write Vulnerability | 8.8 | 0.7% | KEV | 2026-03-12 | |
| CVE-2025-67038 | Lantronix EDS5000, G520, and X300 OS Command Injection | Lantronix | 9.8 | 19.3% | KEV | 2026-03-11 |
| CVE-2026-3798 | Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection | Comfast | 5.8 | 10.9% | 2026-03-09 | |
| CVE-2026-3704 | Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection | Wavlink | 5.8 | 5.3% | 2026-03-08 | |
| CVE-2026-3662 | Wavlink WL-NU516U1 adm.cgi usb_p910 command injection | Wavlink | 5.8 | 10.9% | 2026-03-07 | |
| CVE-2026-3661 | Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection | Wavlink | 5.8 | 10.9% | 2026-03-07 | |
| CVE-2026-3612 | Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection | Wavlink | 8.6 | 10.0% | 2026-03-06 | |
| CVE-2026-20131 | Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability | Cisco | 10.0 | 42.7% | KEV | 2026-03-04 |
| CVE-2026-20079 | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability | Cisco | 10.0 | 88.2% | KEV | 2026-03-04 |
| CVE-2026-3485 | D-Link DIR-868L SSDP Service sub_1BF84 os command injection | D-Link | 10.0 | 6.7% | 2026-03-03 | |
| CVE-2026-1492 | User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration | wpeverest | 9.8 | 28.0% | 2026-03-03 | |
| CVE-2026-21385 | Integer Overflow or Wraparound in Graphics | Qualcomm, Inc. | 7.8 | 1.3% | KEV | 2026-03-02 |
| CVE-2026-28517 | openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter | openDCIM | 9.3 | 9.2% | 2026-02-27 | |
| CVE-2026-22719 | VMware Aria Operations command injection vulnerability | VMware | 8.1 | 17.7% | KEV | 2026-02-25 |
| CVE-2026-21902 | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root | Juniper Networks | 9.8 | 18.0% | 2026-02-25 | |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability | Cisco | 5.4 | 25.0% | KEV | 2026-02-25 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | Cisco | 10.0 | 88.5% | KEV | 2026-02-25 |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability | Cisco | 7.5 | 7.1% | KEV | 2026-02-25 |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Cisco | 6.5 | 31.8% | KEV | 2026-02-25 |
| CVE-2026-3101 | Intelbras TIP 635G Ping os command injection | Intelbras | 6.5 | 6.6% | 2026-02-24 | |
| CVE-2026-3066 | HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3065 | HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3064 | HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3040 | DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection | DrayTek | 5.8 | 7.2% | 2026-02-23 | |
| CVE-2026-2956 | qinming99 dst-admin restore revertBackup command injection | qinming99 | 6.5 | 8.8% | 2026-02-22 | |
| CVE-2026-2952 | Vaelsys HTTP POST Request tree_server.php os command injection | - | 7.5 | 7.3% | 2026-02-22 | |
| CVE-2026-2944 | Tosei Online Store Management System ネット店舗管理システム HTTP POST Request monitor.php system os command injection | Tosei | 7.5 | 7.3% | 2026-02-22 | |
| CVE-2026-2041 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability | Nagios | 7.2 | 73.7% | 2026-02-20 | |
| CVE-2026-2043 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability | Nagios | 7.2 | 73.7% | 2026-02-20 | |
| CVE-2026-2847 | UTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection | UTT | 8.6 | 7.5% | 2026-02-20 | |
| CVE-2026-2846 | UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection | UTT | 8.6 | 7.5% | 2026-02-20 | |
| CVE-2026-2824 | Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection | Comfast | 6.5 | 11.5% | 2026-02-20 | |
| CVE-2026-2823 | Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection | Comfast | 6.5 | 11.5% | 2026-02-20 | |
| CVE-2026-2329 | Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow | Grandstream | 9.3 | 40.6% | 2026-02-18 | |
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | Dell | 10.0 | 13.3% | KEV | 2026-02-17 |
| CVE-2026-2615 | Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection | Wavlink | 8.6 | 7.8% | 2026-02-17 | |
| CVE-2026-2537 | Comfast CF-E4 HTTP POST Request mbox-config command injection | Comfast | 5.8 | 25.3% | 2026-02-16 | |
| CVE-2026-2535 | Comfast CF-N1 V2 mbox-config sub_44AB9C command injection | Comfast | 6.5 | 14.0% | 2026-02-16 | |
| CVE-2026-2534 | Comfast CF-N1 V2 mbox-config sub_44AC4C command injection | Comfast | 6.5 | 13.5% | 2026-02-16 | |
| CVE-2026-2530 | Wavlink WL-WN579A3 wireless.cgi AddMac command injection | Wavlink | 6.5 | 8.2% | 2026-02-16 | |
| CVE-2026-2528 | Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection | Wavlink | 6.5 | 8.2% | 2026-02-16 | |
| CVE-2026-2527 | Wavlink WL-WN579A3 login.cgi command injection | Wavlink | 6.5 | 8.5% | 2026-02-16 | |
| CVE-2026-2526 | Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection | Wavlink | 6.5 | 8.2% | 2026-02-16 | |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability | 8.8 | 55.1% | KEV | 2026-02-13 | |
| CVE-2026-25108 | Soliton Systems K.K FileZen OS Command Injection Vulnerability | Soliton Systems K.K. | 8.8 | 5.1% | KEV | 2026-02-13 |
| CVE-2026-20700 | Apple Multiple Buffer Overflow Vulnerability | Apple | 7.8 | 1.4% | KEV | 2026-02-11 |
| CVE-2026-1357 | Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload | wpvividplugins | 9.8 | 33.3% | 2026-02-11 | |
| CVE-2026-20841 | Windows Notepad App Remote Code Execution Vulnerability | Microsoft | 7.8 | 12.7% | 2026-02-10 | |
| CVE-2026-21249 | Windows NTLM Spoofing Vulnerability | Microsoft | 3.3 | 11.4% | 2026-02-10 | |
| CVE-2026-21525 | Windows Remote Access Connection Manager Denial of Service Vulnerability | Microsoft | 6.2 | 4.8% | KEV | 2026-02-10 |
| CVE-2026-21514 | Microsoft Word Security Feature Bypass Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2026-02-10 |
| CVE-2026-21510 | Windows Shell Security Feature Bypass Vulnerability | Microsoft | 8.8 | 24.2% | KEV | 2026-02-10 |
| CVE-2026-21513 | MSHTML Framework Security Feature Bypass Vulnerability | Microsoft | 8.8 | 15.6% | KEV | 2026-02-10 |
| CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.1% | KEV | 2026-02-10 |
| CVE-2026-21519 | Desktop Window Manager Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.5% | KEV | 2026-02-10 |
| CVE-2026-0652 | Remote Code Execution on TP-Link Tapo C260 by Guest User | TP-Link Systems Inc. | 8.7 | 22.4% | 2026-02-10 | |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Fortinet | 5.3 | 29.6% | KEV | 2026-02-10 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | Ivanti | 8.6 | 87.9% | KEV | 2026-02-10 |
| CVE-2026-2260 | D-Link DCS-931L setSysAdmin os command injection | D-Link | 8.6 | 5.3% | 2026-02-10 | |
| CVE-2026-2227 | D-Link DCS-931L setSystemAdmin doSystem command injection | D-Link | 5.8 | 6.2% | 2026-02-09 | |
| CVE-2026-2188 | UTT 进取 521G formPdbUpConfig sub_446B18 os command injection | UTT | 8.6 | 6.8% | 2026-02-08 | |
| CVE-2026-2184 | Great Developers Certificate Generation System csv.php os command injection | Great Developers | 7.5 | 10.3% | 2026-02-08 | |
| CVE-2026-2182 | UTT 进取 521G setSysAdm doSystem command injection | UTT | 8.6 | 8.9% | 2026-02-08 | |
| CVE-2026-2163 | D-Link DIR-600 ssdp.cgi command injection | D-Link | 5.8 | 6.0% | 2026-02-08 | |
| CVE-2026-2142 | D-Link DIR-823X set_qos sub_420688 os command injection | D-Link | 8.6 | 6.0% | 2026-02-08 | |
| CVE-2026-2131 | XixianLiang HarmonyOS-mcp-server input_text os command injection | XixianLiang | 6.5 | 15.9% | 2026-02-08 | |
| CVE-2026-2082 | D-Link DIR-823X set_mac_clone os command injection | D-Link | 5.8 | 5.2% | 2026-02-07 | |
| CVE-2026-2081 | D-Link DIR-823X set_password os command injection | D-Link | 5.8 | 5.6% | 2026-02-07 | |
| CVE-2026-2080 | UTT HiPER 810 formUser setSysAdm command injection | UTT | 8.6 | 9.9% | 2026-02-07 | |
| CVE-2026-1731 | Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | BeyondTrust | 9.9 | 91.0% | KEV | 2026-02-06 |
| CVE-2026-21643 | Fortinet FortiClient EMS SQL Injection Vulnerability | Fortinet | 9.1 | 93.7% | KEV | 2026-02-06 |
| CVE-2026-2000 | DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection | DCN | 5.8 | 18.1% | 2026-02-06 | |
| CVE-2026-1207 | Potential SQL injection via raster lookups on PostGIS | djangoproject | 5.4 | 13.3% | 2026-02-03 | |
| CVE-2025-15556 | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification | notepad-plus-plus | 7.7 | 1.7% | KEV | 2026-02-03 |
| CVE-2026-25137 | NixOs Odoo database and filestore publicly accessible with default odoo configuration | NixOS | 9.1 | 10.5% | 2026-02-02 | |
| CVE-2026-22778 | vLLM leaks a heap address when PIL throws an error | vllm-project | 9.8 | 11.2% | 2026-02-02 | |
| CVE-2026-0599 | Unbounded External Image Fetch in Validation Leads to Resource-Exhaustion DoS in huggingface/text-generation-inference | huggingface | 7.5 | 29.9% | 2026-02-02 | |
| CVE-2026-25253 | - | OpenClaw | 8.8 | 24.4% | 2026-02-01 | |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Ivanti | 9.8 | 98.6% | KEV | 2026-01-29 |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Ivanti | 9.8 | 98.7% | KEV | 2026-01-29 |
| CVE-2026-1056 | Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal | inc2734 | 9.8 | 13.5% | 2026-01-28 | |
| CVE-2025-40551 | SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability | SolarWinds | 9.8 | 84.2% | KEV | 2026-01-28 |
| CVE-2025-40536 | SolarWinds Web Help Desk Security Control Bypass Vulnerability | SolarWinds | 8.1 | 73.6% | KEV | 2026-01-28 |
| CVE-2026-1506 | D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection | D-Link | 8.6 | 5.6% | 2026-01-28 | |
| CVE-2026-1505 | D-Link DIR-615 URL Filter set_temp_nodes.php os command injection | D-Link | 8.6 | 5.1% | 2026-01-28 | |
| CVE-2026-24858 | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Fortinet | 9.4 | 85.8% | KEV | 2026-01-27 |
| CVE-2026-1470 | Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node. | - | 9.9 | 20.7% | 2026-01-27 |