Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,367
- High8,670
- Medium6,681
- Low718
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-516879.1 CRI30.1%
——9Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.16dCVE-2024-9613—30.1%
——9——CVE-2021-34576—30.1%
——9——CVE-2006-4082—30.1%
——9——CVE-2020-25723—30.1%
——9——CVE-2019-18833—30.1%
——9——CVE-2019-25538—30.1%
——9——CVE-2021-26274—30.1%
——9——CVE-2026-516717.5 HIG30.1%
——9Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2021-37192—30.1%
——9——CVE-2026-12755—30.1%
——9——CVE-2026-516487.5 HIG30.1%
——9Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2023-53917—30.1%
——9——CVE-2018-0671—30.1%
——9——CVE-2025-59134—30.1%
——9——CVE-2016-9806—30.1%
——9——CVE-2024-10046—30.1%
——9——CVE-2025-60211—30.1%
——9——CVE-2025-13765—30.1%
——9——CVE-2025-11721—30.1%
——9——CVE-2026-516597.5 HIG30.1%
——9Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2024-37123—30.1%
——9——CVE-2023-32643—30.1%
——9——CVE-2026-516247.5 HIG30.1%
——9Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-926267.5 HIG30.1%
——9Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.
The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.2dCVE-2025-59579—30.1%
——9——CVE-2026-516217.5 HIG30.1%
——9Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-22228—30.1%
——9——CVE-2026-516277.5 HIG30.1%
——9Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-494596.1 MED30.1%
——9DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.59dCVE-2020-29567—30.1%
——9——CVE-2024-28782—30.1%
——9——CVE-2026-517009.1 CRI30.1%
——9Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-28825—30.1%
——9——CVE-2026-208097.8 HIG30.1%
——9Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.50dCVE-2023-46146—30.1%
——9——CVE-2021-37190—30.1%
——9——CVE-2026-516237.5 HIG30.1%
——9Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-516229.1 CRI30.1%
——9Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-516417.5 HIG30.1%
——9Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17d