SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,244 results · page 22 of 785

CVESummaryPriorityPublished
CVE-2026-51741Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%1 September 2026
CVE-2026-18765Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc.CRITICAL 9.8EPSS 0.26%1 September 2026
CVE-2026-84200When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g.,…CRITICAL 9.4EPSS 0.18%1 September 2026
CVE-2026-84189An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab.CRITICAL 9.2EPSS 0.27%1 September 2026
CVE-2026-18550The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6.CRITICAL 9.8EPSS 0.33%1 September 2026
CVE-2023-54356Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints.CRITICAL 9.3EPSS 0.15%1 September 2026
CVE-2026-4813A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely.CRITICAL 9.4EPSS 0.34%1 September 2026
CVE-2026-78319A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition.CRITICAL 9.3EPSS 0.40%1 September 2026
CVE-2026-75865The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an…CRITICAL 9.8EPSS 0.51%1 September 2026
CVE-2026-67394A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5.CRITICAL 9.0EPSS 1.29%1 September 2026
CVE-2026-82971A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11.CRITICAL 9.3EPSS 1.88%31 August 2026
CVE-2026-82226Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.CRITICAL 9.8EPSS 0.31%31 August 2026
CVE-2026-81780Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.CRITICAL 10.0EPSS 0.29%31 August 2026
CVE-2026-81779Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.CRITICAL 10.0EPSS 0.29%31 August 2026
CVE-2026-81763Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.CRITICAL 9.3EPSS 0.24%31 August 2026
CVE-2026-81756Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.CRITICAL 9.3EPSS 0.25%31 August 2026
CVE-2026-81293Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.CRITICAL 9.3EPSS 0.24%31 August 2026
CVE-2026-79408An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.CRITICAL 9.8EPSS 1.17%31 August 2026
CVE-2026-38577Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.CRITICAL 9.8EPSS 0.33%31 August 2026
CVE-2026-51740Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51738Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51736Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.36%31 August 2026
CVE-2026-51734Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51733Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51731Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.36%31 August 2026
CVE-2026-53552A user holding the manager role (or any role that includes the FileSync / EditProject permission) in their own namespace can read, write, or delete files in any project across the install, and can rewrite any project's git remote URL by submitting the…CRITICAL 9.6EPSS 0.20%31 August 2026
CVE-2026-79748Authentication is required, but there is no authorization check restricting these endpoints to admins, and there is no allowlist/sanitization on the command and args fields.CRITICAL 9.9EPSS 0.33%31 August 2026
CVE-2026-51730Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51729Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51728Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.35%31 August 2026
CVE-2026-51726Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.36%31 August 2026
CVE-2026-51725Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51724Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.35%31 August 2026
CVE-2026-51723Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51722Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51721Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51720Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-76133Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication mechanism and facilitate unauthorized access.CRITICAL 9.3EPSS 0.40%31 August 2026
CVE-2026-73819An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.CRITICAL 9.3EPSS 0.53%31 August 2026
CVE-2026-51718Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.35%31 August 2026
CVE-2026-51717Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51715Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.35%31 August 2026
CVE-2026-51713Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51711Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51710Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.29%31 August 2026
CVE-2026-51709Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51708Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51705Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.44%31 August 2026
CVE-2026-51701Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.36%31 August 2026
CVE-2026-51700Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.CRITICAL 9.1EPSS 0.36%31 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.