Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-8262 — Devs Palace ERP Online chart-save cross site scripting

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack ma…

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.9 MEDIUM
CVE-2026-8261 — Squirrel sqobject.cpp Load heap-based overflow

A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attac…

squirrel | Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
9.0 HIGH
CVE-2026-8260 — D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow

A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipu…

dcs-935l_firmware | Remote | Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
7.2 HIGH
CVE-2026-8259 — Tenda AC6 httpd telnet os command injection

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip lea…

ac6_firmware ac6 | Remote | Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.3 MEDIUM
CVE-2026-8258 — Squirrel sqstdstring.cpp validate_format stack-based overflow

A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The at…

squirrel | Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
3.3 LOW
CVE-2026-8257 — WebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertion

A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a…

binaryen | Denial of Service
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
3.3 LOW
CVE-2026-8256 — Devs Palace ERP Online mr-save cross site scripting

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scriptin…

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
3.3 LOW
CVE-2026-8255 — Devs Palace ERP Online add_new_customer cross site scripting

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack c…

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
3.3 LOW
CVE-2026-8254 — Devs Palace ERP Online sales_save cross site scripting

A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross si…

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
3.3 LOW
CVE-2026-8253 — Devs Palace ERP Online purchase_save cross site scripting

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross …

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.3 MEDIUM
CVE-2026-8252 — Open5GS SMF smf_nsmf_handle_create_data_in_hsmf null pointer dereference

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference…

open5gs | Remote | Denial of Service
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.3 MEDIUM
CVE-2026-8251 — Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service

A vulnerability was found in Open5GS up to 2.7.7. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation resu…

open5gs | Remote | Denial of Service
May 10, 2026 May 11, 2026
May 10, 2026
May 11, 2026
4.3 MEDIUM
CVE-2026-8250 — Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service

A vulnerability has been found in Open5GS up to 2.7.7. This affects the function smf_n4_build_qos_flow_to_modify_list of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to …

open5gs | Remote | Denial of Service
May 10, 2026 May 11, 2026
May 10, 2026
May 11, 2026
4.3 MEDIUM
CVE-2026-8249 — Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service

A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation cause…

open5gs | Remote | Denial of Service
May 10, 2026 May 11, 2026
May 10, 2026
May 11, 2026
4.3 MEDIUM
CVE-2026-8248 — Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service

A vulnerability was detected in Open5GS up to 2.7.7. The affected element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. The manipulation…

open5gs | Remote | Denial of Service
May 10, 2026 May 11, 2026
May 10, 2026
May 11, 2026
7.5 HIGH
CVE-2026-8177 — XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing …

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UT…

Remote | Memory Corruption
May 10, 2026 May 11, 2026
May 10, 2026
May 11, 2026
6.5 MEDIUM
CVE-2026-45191 — Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero …

Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validatio…

net\ | Remote | Misconfiguration
May 10, 2026 May 11, 2026
May 10, 2026
May 11, 2026
0.0 NA
CVE-2026-45190 — Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and C…

Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass. Inputs containing a trailing newline or non-ASCII digit chara…

net\ | Misconfiguration
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
0.0 NA
CVE-2026-45180 — Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids

Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on ano…

| Information Disclosure
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
0.0 NA
CVE-2026-45179 — Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses

Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host o…

| Information Disclosure
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
Showing 20 of 5646 Results