Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-9306 — QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authori…

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjou…

| Authorization
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9305 — QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection

A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. Th…

| Injection
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9304 — calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The ma…

| Server-Side Request Forgery
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9303 — calcom cal.diy cross-site request forgery

A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Th…

| Cross-Site Request Forgery
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9302 — 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of …

| Injection
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9301 — omec-project amf NGReset Message memory corruption

A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. Th…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9300 — omec-project amf NGSetupRequest memory corruption

A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be e…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-46300 — net: skbuff: preserve shared-frag marker during coalescing

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_s…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-43503 — net: skbuff: propagate shared-frag marker through frag-transfer helpers

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9299 — omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption

A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memo…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9298 — omec-project amf PathSwitchRequest memory corruption

A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality of the component PathSwitchRequest Handler. The manipulation results in memory…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9297 — Edimax BR-6428NS POST Request formWlbasic command injection

A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. The manipulation of th…

| Injection
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9296 — Edimax BR-6428NS POST Request formWlanM system command injection

A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing a manipulation of the argument…

| Injection
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9295 — Edimax BR-6428NS POST Request formWirelessTbl buffer overflow

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipul…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9294 — Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manip…

| Memory Corruption
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-6419 — Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secr…

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check …

| Authorization
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-6897 — Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in…

| Authorization
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-9284 — WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Man…

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc…

| Authorization
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-6895 — Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secr…

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is du…

| Authorization
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
0.0 NA
CVE-2026-6898 — WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate…

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions…

| Authorization
May 23, 2026 May 23, 2026
May 23, 2026
May 23, 2026
Showing 20 of 6034 Results