Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25534
Total
1899
Critical
7798
High
8005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2018-25416 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. … | May 30, 2026 |
| CVE-2018-25415 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. … | May 30, 2026 |
| CVE-2018-25414 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. … | May 30, 2026 |
| CVE-2018-25413 | HIGH | 8.2 | AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. … | May 30, 2026 |
| CVE-2018-25412 | CRITICAL | 9.8 | Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted … | May 30, 2026 |
| CVE-2018-25411 | HIGH | 8.2 | MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' … | May 30, 2026 |
| CVE-2018-25410 | HIGH | 7.1 | SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers … | May 30, 2026 |
| CVE-2018-25409 | HIGH | 8.8 | SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers … | May 30, 2026 |
| CVE-2018-25408 | HIGH | 7.5 | The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the … | May 30, 2026 |
| CVE-2018-25407 | HIGH | 8.2 | eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. … | May 30, 2026 |
| CVE-2018-25406 | HIGH | 8.2 | eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. … | May 30, 2026 |
| CVE-2018-25405 | HIGH | 8.2 | eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. … | May 30, 2026 |
| CVE-2026-10120 | HIGH | 8.8 | A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name … | May 30, 2026 |
| CVE-2026-10119 | HIGH | 8.8 | A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name … | May 30, 2026 |
| CVE-2026-46242 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under … | May 30, 2026 |
| CVE-2026-10117 | MEDIUM | 4.3 | A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead … | May 30, 2026 |
| CVE-2026-10116 | MEDIUM | 4.3 | A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications … | May 30, 2026 |
| CVE-2026-10115 | MEDIUM | 4.3 | A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such … | May 30, 2026 |
| CVE-2026-10114 | MEDIUM | 4.3 | A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared … | May 30, 2026 |
| CVE-2026-9757 | HIGH | 7.5 | The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, … | May 30, 2026 |
| CVE-2026-7465 | HIGH | 8.8 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, … | May 30, 2026 |
| CVE-2026-7459 | HIGH | 7.5 | The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, … | May 30, 2026 |
| CVE-2026-10113 | MEDIUM | 4.3 | A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared … | May 30, 2026 |
| CVE-2026-5071 | MEDIUM | 6.1 | The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in … | May 30, 2026 |
| CVE-2026-10112 | LOW | 2.4 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name … | May 30, 2026 |