Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25534
Total
1899
Critical
7798
High
8005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10158 | HIGH | 8.8 | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name … | May 31, 2026 |
| CVE-2026-10157 | HIGH | 7.3 | A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. … | May 31, 2026 |
| CVE-2026-10156 | MEDIUM | 4.3 | A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a … | May 31, 2026 |
| CVE-2026-10155 | MEDIUM | 4.7 | A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component … | May 31, 2026 |
| CVE-2026-10154 | MEDIUM | 4.3 | A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the … | May 31, 2026 |
| CVE-2026-10153 | MEDIUM | 4.3 | A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument … | May 30, 2026 |
| CVE-2026-10152 | MEDIUM | 6.3 | A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. … | May 30, 2026 |
| CVE-2026-10127 | MEDIUM | 6.3 | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This … | May 30, 2026 |
| CVE-2026-10126 | HIGH | 8.8 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component … | May 30, 2026 |
| CVE-2026-8594 | UNKNOWN | — | Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line … | May 30, 2026 |
| CVE-2026-10125 | HIGH | 8.8 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request … | May 30, 2026 |
| CVE-2026-10124 | HIGH | 8.8 | A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing … | May 30, 2026 |
| CVE-2026-10123 | HIGH | 8.8 | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results … | May 30, 2026 |
| CVE-2026-10122 | HIGH | 8.8 | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads … | May 30, 2026 |
| CVE-2026-10121 | HIGH | 8.8 | A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument … | May 30, 2026 |
| CVE-2018-25426 | HIGH | 7.5 | WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer … | May 30, 2026 |
| CVE-2018-25425 | HIGH | 8.2 | Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and … | May 30, 2026 |
| CVE-2018-25424 | HIGH | 8.2 | Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and … | May 30, 2026 |
| CVE-2018-25423 | MEDIUM | 6.2 | Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste … | May 30, 2026 |
| CVE-2018-25422 | HIGH | 8.2 | MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id … | May 30, 2026 |
| CVE-2018-25421 | MEDIUM | 6.5 | Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send … | May 30, 2026 |
| CVE-2018-25420 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. … | May 30, 2026 |
| CVE-2018-25419 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. … | May 30, 2026 |
| CVE-2018-25418 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. … | May 30, 2026 |
| CVE-2018-25417 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. … | May 30, 2026 |