Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-8739 — Sanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded key

A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigC…

Remote | Cryptography
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
6.5 MEDIUM
CVE-2026-8738 — Sanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pa…

A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file public…

Remote | Authorization
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
5.5 MEDIUM
CVE-2026-8737 — Sanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing auth…

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListD…

Remote | Authentication
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
4.3 MEDIUM
CVE-2026-8736 — Oinone Pamirs RestController LocalFileClient.java request.getParameter path traversal

A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Perfor…

| Path Traversal
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
6.5 MEDIUM
CVE-2026-8735 — Oinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserialization

A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulat…

Remote | Injection
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
7.5 HIGH
CVE-2026-8734 — Oinone Pamirs queryListByWrapper RSQLToSQLNodeConnector.makeVariable sql injection

A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interface. This manipulatio…

Remote | Injection
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
7.5 HIGH
CVE-2026-8733 — Investintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflow

A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based …

Remote | Memory Corruption
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
4.3 MEDIUM
CVE-2026-8731 — Open5GS NRF client.c ogs_sbi_client_add denial of service

A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool …

Remote | Denial of Service
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
4.3 MEDIUM
CVE-2026-8730 — Open5GS NRF context.c ogs_sbi_nf_instance_set_id denial of service

A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manipulation of the argument nfI…

Remote | Denial of Service
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
4.3 MEDIUM
CVE-2026-8729 — Open5GS NRF message.c denial of service

A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/s…

Remote | Denial of Service
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
4.3 MEDIUM
CVE-2026-8728 — Open5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of service

A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. S…

Remote | Denial of Service
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
8.8 HIGH
CVE-2026-8719 — AI Engine 3.4.9 - Authenticated (Subscriber+) Privilege Escalation via Missing Authorizat…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in t…

Remote | Authorization
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
7.5 HIGH
CVE-2026-8725 — CoreWorxLab CAAL test-hass Endpoint webhooks.py server-side request forgery

A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation cau…

Remote | Server-Side Request Forgery
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
5.8 MEDIUM
CVE-2026-8724 — Dataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection

A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results …

Remote | Injection
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
6.3 MEDIUM
CVE-2026-8723 — qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesO…

### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not ha…

Remote | Misconfiguration
May 17, 2026 May 17, 2026
May 17, 2026
May 17, 2026
8.2 HIGH
CVE-2026-46728 — Das U-Boot FIT Signature Verification Bypass

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
5.4 MEDIUM
CVE-2021-47981 — Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription par…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
7.1 HIGH
CVE-2021-47980 — Fuel CMS 1.4.13 Blind SQL Injection via col Parameter

Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log i…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2021-47979 — WordPress Plugin Backup and Restore 1.0.3 Arbitrary File Deletion

WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers …

Remote | Path Traversal
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.9 MEDIUM
CVE-2021-47978 — ProcessMaker 3.5.4 Local File Inclusion via Path Traversal

ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send req…

| Path Traversal
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
Showing 20 of 6233 Results