Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 HIGH
CVE-2026-9406 — Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a m…

a8000ru_firmware | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
10.0 HIGH
CVE-2026-9405 — Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Perf…

a8000ru_firmware | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
10.0 HIGH
CVE-2026-9404 — Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulat…

a8000ru_firmware | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9403 — Edimax BR-6675nD POST Request formWlSiteSurvey buffer overflow

A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. This manipul…

br-6675nd | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9402 — Edimax BR-6675nD POST Request formWlanMP command injection

A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. The manipulation of the argum…

br-6675nd | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9401 — Edimax BR-6675nD POST Request formWanTcpipSetup buffer overflow

A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. The manipulation of th…

br-6675nd | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9400 — Edimax BR-6675nD POST Request formUSBStorage command injection

A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request Handler. Executing a manipulation of th…

br-6675nd | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
3.5 LOW
CVE-2026-48832 — SPIP ecrire Open Redirect

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

spip | Remote | Misconfiguration
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9399 — Edimax BR-6675nD POST Request formsetPPPoE buffer overflow

A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file /goform/formsetPPPoE of the component POST Request Handler. Performing a manipu…

br-6675nd | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.3 HIGH
CVE-2026-48831 — Wine MIME Handler Escalation Vulnerability

Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to b…

wine | Misconfiguration
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
3.1 LOW
CVE-2026-9398 — Besen BS20 EV Charging Station BLE/WiFi authentication replay

A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown part of the component BLE/WiFi. Such manipulation leads to authentication bypass b…

bs20_ev_charging_station | Authentication
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
8.2 HIGH
CVE-2026-9397 — Besen BS20 EV Charging Station OTA Update Installation improper authorization

A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulati…

bs20_ev_charging_station | Remote | Authorization
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
3.7 LOW
CVE-2026-9396 — Besen BS20 EV Charging Station Firmware Version Check ui layer

A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is an unknown functionality of the component Firmware Version Check. The manipulat…

bs20_ev_charging_station | Remote | Misconfiguration
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
3.5 LOW
CVE-2026-9395 — Besen BS20 EV Charging Station BLE/UDP insufficiently protected credentials

A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation leads to insufficiently protected credentia…

bs20_ev_charging_station | Authentication
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
3.1 LOW
CVE-2026-9394 — Besen BS20 EV Charging Station Bluetooth Low Energy weak password

A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipulation can lead to w…

bs20_ev_charging_station | Authentication
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9393 — H3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow

A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer ove…

magic_b0_firmware | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9389 — Tenda F456 L7Im frmL7ImForm buffer overflow

A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to buffer overflow. The a…

f456_firmware | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
10.0 HIGH
CVE-2026-9388 — Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface.…

a8000ru_firmware | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
10.0 HIGH
CVE-2026-9387 — Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interfa…

a8000ru_firmware | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
10.0 HIGH
CVE-2026-9386 — Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipu…

a8000ru_firmware | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
Showing 20 of 6714 Results