Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-7683 — Edimax BR-6428nC Web setWAN command injection

A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserNam…

Remote | Injection
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
6.5 MEDIUM
CVE-2026-7682 — Edimax BR-6208AC L2TP Mode setWAN command injection

A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPU…

Remote | Injection
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
0.0 NA
CVE-2026-5337 — Frontend File Manager Plugin <= 23.6 - Subscriber+ Arbitrary Download Access via IDOR

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability ex…

| Authorization
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
6.5 MEDIUM
CVE-2026-7681 — jsbroks COCO Annotator Dataset API datasets.py authorization

A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the file backend/webserver/api/datasets.py of the comp…

Remote | Authorization
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
4.3 MEDIUM
CVE-2026-7680 — jsbroks COCO Annotator Data Endpoint datasets.py path traversal

A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipu…

Remote | Path Traversal
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
7.2 HIGH
CVE-2026-5063 — NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key …

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to,…

Remote | Cross-Site Scripting
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
7.5 HIGH
CVE-2026-7679 — YunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authentication

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/servi…

Remote | Authentication
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
6.5 MEDIUM
CVE-2026-7678 — YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection

A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoView…

Remote | Injection
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
4.0 MEDIUM
CVE-2026-7677 — kerwincui FastBee System Notice SysNoticeController.java add cross site scripting

A vulnerability was determined in kerwincui FastBee up to 1.2.1. The impacted element is the function Add of the file springboot/fastbee-admin/src/main/java/com/fastbee/web/controller/system/SysNotic…

Remote | Cross-Site Scripting
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
4.3 MEDIUM
CVE-2026-7676 — kerwincui FastBee Tool Download Endpoint ToolController.java ToolController.download path…

A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/control…

Remote | Path Traversal
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
9.0 HIGH
CVE-2026-7675 — Shenzhen Libituo Technology LBT-T300-HW1 apply.cgi start_lan buffer overflow

A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. Impacted is the function start_lan of the file /apply.cgi. The manipulation of the argument Channel/ApCliSsid l…

Remote | Memory Corruption
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
9.0 HIGH
CVE-2026-7674 — Shenzhen Libituo Technology LBT-T300-HW1 Web Management start_single_service buffer overf…

A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation…

Remote | Memory Corruption
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
5.8 MEDIUM
CVE-2026-7673 — crmeb_java Admin Upload UploadServiceImpl.java unrestricted upload

A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of t…

Remote | Misconfiguration
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
0.0 NA
CVE-2026-40561 — Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header …

Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both head…

| Misconfiguration
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
6.5 MEDIUM
CVE-2026-7672 — youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection

A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.jav…

Remote | Injection
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
3.7 LOW
CVE-2026-7671 — CodeWise Tornet Scooter Mobile App TwoFactor excessive authentication

A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restr…

Remote | Authentication
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
7.5 HIGH
CVE-2026-7670 — Jinher OA UserSel.aspx sql injection

A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manipulation of the argument DeptIDList causes sql inje…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.3 MEDIUM
CVE-2026-7669 — sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deseria…

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transf…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7668 — MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulatio…

Remote | Memory Corruption
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7653 — r-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection

A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
Showing 20 of 5564 Results