Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-8233 — Dotouch XproUPF access control

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of com…

| Authorization
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8230 — Wavlink NU516U1 login.cgi sys_login1 os command injection

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8229 — Wavlink NU516U1 wireless.cgi WifiBasic os command injection

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypTy…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8228 — Wavlink NU516U1 wireless.cgi advance os command injection

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8227 — Wavlink NU516U1 adm.cgi wzdapMesh os command injection

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be init…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8226 — Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8225 — Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of service

A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation …

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-7568 — Signed integer overflow in metaphone()

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the cur…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
2.9 LOW
CVE-2026-7262 — NULL pointer dereference in SOAP apache:Map decoder with missing <value>

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which check…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-7261 — SoapServer session-persisted object use-after-free via SOAP header fault

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted acr…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
2.1 LOW
CVE-2026-7259 — Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, re…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-7258 — Out-of-bounds read in urldecode() on NetBSD

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
7.3 HIGH
CVE-2026-6735 — XSS within PHP-FPM status endpoint

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause t…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
9.5 CRITICAL
CVE-2026-6722 — Use-After-Free in SOAP using Apache map

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global m…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
7.4 HIGH
CVE-2025-14179 — SQL injection in pdo_firebird via NUL bytes in quoted strings

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
0.0 NA
CVE-2026-8232 — Dotouch XproUPF UPF Process libvlib.so vlib_worker_loop denial of service

A vulnerability was found in Dotouch XproUPF 2.0.0-release-088aa7c4. This impacts the function vlib_worker_loop in the library /usr/xpro/upf/tools/libs/libvlib.so of the component UPF Process. The ma…

| Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
0.0 NA
CVE-2026-8231 — CodeAstro Online Catering Ordering System deleteorder.php sql injection

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql inject…

| Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-7263 — DoS attack via DOMNode::C14N()

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML docu…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-6104 — Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectl…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8224 — Open5GS PCF context.c pcf_sess_set_ipv6prefix denial of service

A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of …

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
Showing 20 of 5577 Results