Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25534
Total
1899
Critical
7798
High
8005
Medium
CVE ID Severity Score Description Published
CVE-2018-25416 HIGH 8.2 AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. … May 30, 2026
CVE-2018-25415 HIGH 8.2 AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. … May 30, 2026
CVE-2018-25414 HIGH 8.2 AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. … May 30, 2026
CVE-2018-25413 HIGH 8.2 AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. … May 30, 2026
CVE-2018-25412 CRITICAL 9.8 Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted … May 30, 2026
CVE-2018-25411 HIGH 8.2 MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' … May 30, 2026
CVE-2018-25410 HIGH 7.1 SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers … May 30, 2026
CVE-2018-25409 HIGH 8.8 SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers … May 30, 2026
CVE-2018-25408 HIGH 7.5 The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the … May 30, 2026
CVE-2018-25407 HIGH 8.2 eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. … May 30, 2026
CVE-2018-25406 HIGH 8.2 eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. … May 30, 2026
CVE-2018-25405 HIGH 8.2 eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. … May 30, 2026
CVE-2026-10120 HIGH 8.8 A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name … May 30, 2026
CVE-2026-10119 HIGH 8.8 A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name … May 30, 2026
CVE-2026-46242 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under … May 30, 2026
CVE-2026-10117 MEDIUM 4.3 A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead … May 30, 2026
CVE-2026-10116 MEDIUM 4.3 A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications … May 30, 2026
CVE-2026-10115 MEDIUM 4.3 A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such … May 30, 2026
CVE-2026-10114 MEDIUM 4.3 A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared … May 30, 2026
CVE-2026-9757 HIGH 7.5 The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, … May 30, 2026
CVE-2026-7465 HIGH 8.8 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, … May 30, 2026
CVE-2026-7459 HIGH 7.5 The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, … May 30, 2026
CVE-2026-10113 MEDIUM 4.3 A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared … May 30, 2026
CVE-2026-5071 MEDIUM 6.1 The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in … May 30, 2026
CVE-2026-10112 LOW 2.4 A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name … May 30, 2026