Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-7548 — Totolink NR1800X cstecgi.cgi sub_41A68C command injection

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd result…

| Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7545 — SourceCodester Advanced School Management System checkEmail Endpoint commonController.php…

A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commonController.php of the component checkEmail Endpoi…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
10.0 HIGH
CVE-2026-7538 — Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation o…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-7536 — Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsf_sess_add_by_ip_address of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a…

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-7546 — Totolink NR1800X lighttpd find_host_ip stack-based overflow

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Ho…

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7535 — Open5GS transfer-update denial of service

A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c of the file /namf-comm/v1/ue-con…

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7519 — Fujian Apex LiveBOS Endpoint UploadImage.do path traversal

A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component Endpoint. Such manipulation of the argument filename…

Remote | Path Traversal
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7518 — Open5GS AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_…

A flaw has been found in Open5GS up to 2.7.7. This issue affects the function amf_namf_callback_handle_sdm_data_change_notify of the file /namf-callback/v1/{id}/sdmsubscription-notify of the componen…

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.0 HIGH
CVE-2026-7513 — UTT HiPER 1200GW formRemoteControl strcpy buffer overflow

A vulnerability has been found in UTT HiPER 1200GW up to 2.5.3-170306. The impacted element is the function strcpy of the file /goform/formRemoteControl. The manipulation leads to buffer overflow. Th…

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.0 HIGH
CVE-2026-7512 — UTT HiPER 1200GW formUser strcpy buffer overflow

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-1703. The affected element is the function strcpy of the file /goform/formUser. Executing a manipulation can lead to buffer overflow. The attack …

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.0 HIGH
CVE-2026-5656 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wiresha…

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

| Path Traversal
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.8 HIGH
CVE-2026-5405 — Heap-based Buffer Overflow in Wireshark

RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

| Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.7 MEDIUM
CVE-2026-5404 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark

K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

| Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.8 HIGH
CVE-2026-5403 — Heap-based Buffer Overflow in Wireshark

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

| Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.0 MEDIUM
CVE-2026-22726 — Route Services Firewall Bypass

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure…

Remote | Server-Side Request Forgery
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-7510 — OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulati…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-7508 — Bootstrap CMS Page Creation show.blade.php code injection

A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulat…

Remote | Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7506 — SourceCodester Hotel Management System check sql injection

A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room_type le…

Remote | Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7505 — nextlevelbuilder GoClaw/GoClaw Lite RPC improper authorization

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attac…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-28909 — Apache Container Registry Unauthenticated Registry Credentials Exposure

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

| Misconfiguration
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
Showing 20 of 5807 Results