Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 23 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-51699 | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 31 August 2026 |
| CVE-2026-51698 | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-51152 | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. | CRITICAL 9.1EPSS 0.45% | 31 August 2026 |
| CVE-2026-82970 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. | CRITICAL 10.0EPSS 0.29% | 31 August 2026 |
| CVE-2026-66047 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via… | CRITICAL 9.2EPSS 0.54% | 31 August 2026 |
| CVE-2026-59111 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for… | CRITICAL 9.3EPSS 0.79% | 31 August 2026 |
| CVE-2026-51697 | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.29% | 31 August 2026 |
| CVE-2026-51696 | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.35% | 31 August 2026 |
| CVE-2026-51693 | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.35% | 31 August 2026 |
| CVE-2026-51692 | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.29% | 31 August 2026 |
| CVE-2026-51691 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 31 August 2026 |
| CVE-2026-51690 | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-51689 | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.43% | 31 August 2026 |
| CVE-2026-51687 | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-51686 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 31 August 2026 |
| CVE-2026-51684 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 31 August 2026 |
| CVE-2026-51681 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.29% | 31 August 2026 |
| CVE-2026-51680 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.29% | 31 August 2026 |
| CVE-2026-51679 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.35% | 31 August 2026 |
| CVE-2026-51677 | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.29% | 31 August 2026 |
| CVE-2026-51676 | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-51675 | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-51674 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 31 August 2026 |
| CVE-2026-51672 | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-51670 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 31 August 2026 |
| CVE-2026-51669 | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 31 August 2026 |
| CVE-2026-82695 | The manipulation results in missing authentication. | CRITICAL 9.3EPSS 0.74% | 31 August 2026 |
| CVE-2026-82694 | A vulnerability was identified in Tenda AC1206 15.03.06.23. | CRITICAL 9.3EPSS 0.75% | 31 August 2026 |
| CVE-2026-82693 | A vulnerability was determined in Tenda AC1206 15.03.06.23. | CRITICAL 9.3EPSS 0.79% | 31 August 2026 |
| CVE-2026-82876 | Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid. | CRITICAL 9.3EPSS 0.09% | 31 August 2026 |
| CVE-2026-49003 | Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP,… | CRITICAL 9.6EPSS 0.79% | 31 August 2026 |
| CVE-2026-82874 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. | CRITICAL 9.4EPSS 0.25% | 31 August 2026 |
| CVE-2026-82860 | Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls. | CRITICAL 9.3EPSS 0.30% | 31 August 2026 |
| CVE-2026-82859 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. | CRITICAL 9.3EPSS 0.30% | 31 August 2026 |
| CVE-2026-82858 | @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. | CRITICAL 9.3EPSS 0.19% | 31 August 2026 |
| CVE-2026-82857 | hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. | CRITICAL 9.3EPSS 0.28% | 31 August 2026 |
| CVE-2026-82856 | Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails. | CRITICAL 9.3EPSS 0.28% | 31 August 2026 |
| CVE-2026-82855 | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. | CRITICAL 9.3EPSS 0.33% | 31 August 2026 |
| CVE-2026-82854 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. | CRITICAL 9.3EPSS 1.13% | 31 August 2026 |
| CVE-2026-19410 | An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. | CRITICAL 9.4EPSS 0.20% | 31 August 2026 |
| CVE-2026-82628 | A vulnerability was found in Colorful iGameCenter 2.0.0.81. | CRITICAL 9.3EPSS 0.12% | 31 August 2026 |
| CVE-2026-58574 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. | CRITICAL 9.8EPSS 0.34% | 31 August 2026 |
| CVE-2026-82654 | Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block. | CRITICAL 9.3EPSS 0.22% | 30 August 2026 |
| CVE-2026-82653 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. | CRITICAL 9.3EPSS 0.22% | 30 August 2026 |
| CVE-2026-82645 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. | CRITICAL 9.2EPSS 0.13% | 30 August 2026 |
| CVE-2026-82542 | A weakness has been identified in Tenda HG10 300001138. | CRITICAL 9.3EPSS 0.64% | 30 August 2026 |
| CVE-2026-15980 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. | CRITICAL 9.8EPSS 0.45% | 30 August 2026 |
| CVE-2026-15369 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. | CRITICAL 9.8EPSS 0.40% | 29 August 2026 |
| CVE-2026-82466 | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. | CRITICAL 9.4EPSS 0.34% | 29 August 2026 |
| CVE-2026-82460 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. | CRITICAL 9.3EPSS 0.77% | 29 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.