CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-30864 HIGH

CVE-2026-30864 published: Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

View full advisory →
CVE-2026-13081 UNKNOWN

CVE-2026-13081 published: Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.

View full advisory →
CVE-2025-26238 UNKNOWN

CVE-2025-26238 published: In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

View full advisory →
CVE-2026-13047 UNKNOWN

CVE-2026-13047 published: Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.

View full advisory →
CVE-2025-26237 UNKNOWN

CVE-2025-26237 published: D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.

View full advisory →
CVE-2026-71912 HIGH

CVE-2026-71912 published: Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability...

View full advisory →
CVE-2026-71913 HIGH

CVE-2026-71913 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can tri...

View full advisory →
CVE-2026-71914 CRITICAL

CVE-2026-71914 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger...

View full advisory →
CVE-2026-71915 HIGH

CVE-2026-71915 published: Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trig...

View full advisory →
CVE-2026-71906 HIGH

CVE-2026-71906 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerab...

View full advisory →
CVE-2026-71907 HIGH

CVE-2026-71907 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability v...

View full advisory →
CVE-2026-71908 HIGH

CVE-2026-71908 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote att...

View full advisory →
CVE-2026-71909 HIGH

CVE-2026-71909 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via cra...

View full advisory →
CVE-2026-71910 HIGH

CVE-2026-71910 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vuln...

View full advisory →
CVE-2026-71911 HIGH

CVE-2026-71911 published: Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can ...

View full advisory →
CVE-2026-71904 HIGH

CVE-2026-71904 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A rem...

View full advisory →
CVE-2026-71905 HIGH

CVE-2026-71905 published: Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can...

View full advisory →
CVE-2026-34491 UNKNOWN

CVE-2026-34491 published: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before ...

View full advisory →
CVE-2026-13213 MEDIUM

CVE-2026-13213 published: The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security even before the application has ...

View full advisory →
CVE-2026-16348 UNKNOWN

CVE-2026-16348 published: An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful explo...

View full advisory →