Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 25 May 2026

RSS

918 vulnerabilities published on 25 May 2026

Severity:
Totolink A8000RU Web Management Interface Allows Remote Code Execution
CVE-2026-9478
The Totolink A8000RU's web management interface has a security weakness that allows an attacker to execute commands on the router from a remote location. This could be exploited to gain unauthorized a...
8.9
Totolink A8000RU Web Interface Allows Remote Command Execution
CVE-2026-9477
A security flaw in the Totolink A8000RU's web interface allows an attacker to remotely execute commands on the device. This could potentially allow an attacker to access and control the device. It's r...
8.9
Totolink A8000RU Web Interface Password Settings Vulnerability
CVE-2026-9476
The Totolink A8000RU's web interface has a weakness that allows an attacker to execute unauthorized commands on the device remotely. This means an attacker could potentially access or control your rou...
8.9
Totolink A8000RU Web Interface Allows Unwanted System Commands
CVE-2026-9475
A security flaw in the Totolink A8000RU's web interface could allow an attacker to execute unauthorized system commands. This could happen if someone gains access to the router's management page. To p...
8.9
Totolink A8000RU Web Interface Allows Remote Command Execution
CVE-2026-9458
An attacker can remotely access and control the Totolink A8000RU router's settings through its web interface. This could allow them to make unauthorized changes or disrupt the router's operation. We r...
8.9
Totolink A8000RU Web Management Interface Firmware Upload Vulnerability
CVE-2026-9457
A security issue in the Totolink A8000RU's web management interface allows hackers to potentially execute malicious code on the router remotely. This means that a hacker could gain control over the ro...
8.9
Totolink A8000RU Web Management Interface VPN Configuration Error
CVE-2026-9456
The Totolink A8000RU's web interface has a security issue that allows hackers to execute malicious commands remotely. This means they can potentially take control of the router. We recommend checking ...
8.9
Totolink A8000RU: Malicious File Upload via Web Interface
CVE-2026-9455
A vulnerability in the Totolink A8000RU's web interface allows an attacker to upload malicious files, potentially taking control of the router. This could happen if someone with malicious intent uploa...
8.9
Totolink A8000RU Web Management Interface Command Injection
CVE-2026-9454
The Totolink A8000RU's web management interface has a flaw that can be exploited remotely. This could allow an attacker to execute unauthorized commands on the device. To protect yourself, ensure you ...
8.9
Totolink A8000RU Web Interface L2TP Server Configuration Vulnerability
CVE-2026-9436
A vulnerability in the Totolink A8000RU's web interface allows an attacker to execute unauthorized system commands. This can happen if an attacker sends a malicious request to the router. To protect y...
8.9
Totolink A8000RU Web Management Interface Allows Remote Attack
CVE-2026-9435
The Totolink A8000RU's web management interface has a security flaw that allows hackers to execute unauthorized commands on the device from anywhere. This means an attacker could potentially take cont...
8.9
Totolink A8000RU Web Interface Allows Remote Attack
CVE-2026-9434
The Totolink A8000RU's web interface has a security weakness that could allow hackers to remotely take control of the device. This is a concern because it could allow unauthorized access to your netwo...
8.9
Totolink A8000RU Web Interface Allows Remote Attack
CVE-2026-9433
A security weakness in the Totolink A8000RU's web interface allows an attacker to remotely access and control the device by exploiting a specific function. This could potentially be used to compromise...
8.9
Totolink A8000RU Web Management Interface allows remote code execution
CVE-2026-9432
An attacker can remotely access and control the router's settings, potentially causing harm or disruption. This vulnerability affects the Totolink A8000RU router with software version 7.1cu.643_b20200...
8.9
Totolink A8000RU Web Management Interface Remote Command Execution
CVE-2026-9408
An attacker can remotely execute commands on the Totolink A8000RU router's Web Management Interface, potentially accessing or changing sensitive settings. This is a serious security risk because it al...
8.9
Totolink A8000RU: Remote Code Execution via Web Interface
CVE-2026-9407
A security flaw in the Totolink A8000RU's web interface allows hackers to run malicious code remotely. This could let an attacker take control of the device or use it to launch further attacks. Update...
8.9
Totolink A8000RU Web Management Interface Remote Code Execution
CVE-2026-9406
A weakness in the Totolink A8000RU's web management interface allows an attacker to execute unauthorized commands on the device. This can happen when a specific option is manipulated in a way that all...
8.9
Totolink A8000RU Web Management Interface Remote Code Execution
CVE-2026-9405
The Totolink A8000RU's Web Management Interface has a security flaw that could allow hackers to run their own code on the device. This could happen if an attacker sends a special request to the device...
8.9
SQL Injection in JetEngine Allows Unauthorized Database Access
CVE-2026-42774
Crocoblock JetEngine, a WordPress plugin, has a security issue that allows hackers to access and modify your database. This is a serious problem because it can lead to sensitive data being stolen or m...
9.3
eMagicOne Store Manager SQL Injection Risk: Unauthorised Data Access
CVE-2026-42773
The eMagicOne Store Manager has a security flaw that could allow an attacker to access data they shouldn't. This could happen if an attacker sends malicious input to the software, potentially leading ...
9.3
Szafir SDK Falsely Verifies Digital Signatures
CVE-2026-9058
The Szafir SDK incorrectly reports a digital signature as valid when the signer's certificate cannot be verified. This allows attackers to bypass authentication and impersonate users. Affected applica...
9.3
Spring Security Web: Unauthorized Access via Malicious URLs
ROOT-APP-MAVEN-CVE-2026-22732
A security issue in Spring Security Web could allow attackers to bypass security checks using specially crafted URLs. This affects users of Spring Security Web who have not updated to a patched versio...
9.1
Spring Security Web: Unauthorized Access to Protected Resources
ROOT-APP-MAVEN-CVE-2024-38821
A security issue in Spring Security Web could allow attackers to access resources that are supposed to be restricted. This affects users of the Spring Security Web library. Users should update to a pa...
9.1
StoreApps Smart Manager Privilege Escalation Risk
CVE-2026-45216
An outdated version of StoreApps Smart Manager may allow an attacker to gain higher privileges than intended. This could lead to unauthorized access to sensitive data or system functions. Update to th...
8.8
Edimax EW-7438RPn 1.31 allows remote code execution
CVE-2026-9482
A security issue has been found in the Edimax EW-7438RPn router version 1.31. This issue allows an attacker to execute malicious code remotely. As a result, an attacker could potentially take control ...
7.4