2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51708 | CRITICAL | 9.8 | — | Aug 31, 2026 | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac... |
| CVE-2026-51705 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att... |
| CVE-2026-51701 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a... |
| CVE-2026-51700 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated ... |
| CVE-2026-51699 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51698 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a... |
| CVE-2026-51152 | CRITICAL | 9.1 | — | Aug 31, 2026 | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in... |
| CVE-2026-82970 | CRITICAL | 10 | 0.3% | Aug 31, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePriva... |
| CVE-2026-59111 | CRITICAL | 9.3 | 0.8% | Aug 31, 2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a ... |
| CVE-2026-51697 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker... |
| CVE-2026-51696 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated... |
| CVE-2026-51693 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac... |
| CVE-2026-51692 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att... |
| CVE-2026-51691 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at... |
| CVE-2026-51690 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51689 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack... |
| CVE-2026-51687 | CRITICAL | 9.1 | 0.2% | Aug 31, 2026 | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated ... |
| CVE-2026-51686 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta... |
| CVE-2026-51684 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac... |
| CVE-2026-51681 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack... |
| CVE-2026-51680 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51679 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta... |
| CVE-2026-51677 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker... |
| CVE-2026-51676 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated ... |
| CVE-2026-51675 | CRITICAL | 9.1 | — | Aug 31, 2026 | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now