Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2018-25341 — Smartshop 1 SQL Injection via product.php id Parameter

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …

Remote | Injection
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
8.8 HIGH
CVE-2018-25340 — Smartshop 1 SQL Injection via category.php

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …

Remote | Injection
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
3.7 LOW
CVE-2026-9306 — QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authori…

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjou…

new-api | Remote | Authorization
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9305 — QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection

A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. Th…

new-api | Remote | Injection
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9304 — calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The ma…

cal.diy | Remote | Server-Side Request Forgery
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9303 — calcom cal.diy cross-site request forgery

A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Th…

cal.diy | Remote | Cross-Site Request Forgery
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9302 — 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of …

vps-inventory-monitoring | Remote | Injection
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9301 — omec-project amf NGReset Message memory corruption

A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. Th…

amf | Remote | Memory Corruption
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9300 — omec-project amf NGSetupRequest memory corruption

A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be e…

amf | Remote | Memory Corruption
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
7.8 HIGH
CVE-2026-46300 — net: skbuff: preserve shared-frag marker during coalescing

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from…

linux_kernel | Memory Corruption
May 23, 2026 May 30, 2026
May 23, 2026
May 30, 2026
8.8 HIGH
CVE-2026-43503 — net: skbuff: propagate shared-frag marker through frag-transfer helpers

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_s…

linux_kernel | Memory Corruption
May 23, 2026 May 30, 2026
May 23, 2026
May 30, 2026
6.5 MEDIUM
CVE-2026-9299 — omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption

A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memo…

amf | Remote | Memory Corruption
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9298 — omec-project amf PathSwitchRequest memory corruption

A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality of the component PathSwitchRequest Handler. The manipulation results in memory…

amf | Remote | Memory Corruption
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9297 — Edimax BR-6428NS POST Request formWlbasic command injection

A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. The manipulation of th…

br-6428ns_firmware | Remote | Injection
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9296 — Edimax BR-6428NS POST Request formWlanM system command injection

A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing a manipulation of the argument…

br-6428ns_firmware | Remote | Injection
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9295 — Edimax BR-6428NS POST Request formWirelessTbl buffer overflow

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipul…

br-6428ns_firmware | Remote | Memory Corruption
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9294 — Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manip…

br-6428ns_firmware | Remote | Memory Corruption
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
8.2 HIGH
CVE-2026-9284 — WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Man…

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc…

paypal_payments | Remote | Authorization
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
8.8 HIGH
CVE-2026-6898 — WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate…

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions…

Remote | Authorization
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
8.8 HIGH
CVE-2026-6897 — Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in…

Remote | Authorization
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
Showing 20 of 6725 Results