Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-8193 — Akaunting Invoice PDF Rendering dompdf.php server-side request forgery

A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice PDF Rendering. Executing a manipulation can lead …

Remote | Server-Side Request Forgery
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8192 — Wavlink NU516U1 adm.cgi wzdap os command injection

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8191 — Wavlink NU516U1 adm.cgi wifi_region os command injection

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os …

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8190 — Wavlink NU516U1 adm.cgi wan os command injection

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwa…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8189 — Wavlink NU516U1 adm.cgi wzdrepeater os command injection

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Au…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8188 — Wavlink NU516U1 adm.cgi change_wifi_password os command injection

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/Encryp…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-8198 — Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - U…

The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Information Disclosure in versions up to, and including…

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.9 MEDIUM
CVE-2026-8186 — Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds

A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of the component NF. Performing a manipulation resul…

Remote | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.9 MEDIUM
CVE-2026-8187 — Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumption

A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption…

Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.3 MEDIUM
CVE-2026-8185 — UGREEN CM933 Administrative missing authentication

A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative Interface. Such manipulation leads to missing authe…

| Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.2 HIGH
CVE-2026-3828 — Hikvision Switch Remote Command Execution Vulnerability

Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can e…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-32683 — EZVIZ Cloud API Eavesdropping Vulnerability

Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to…

| Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.8 MEDIUM
CVE-2026-1749 — HikCentral Professional Unauthenticated Admin Privilege Escalation

There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

hikcentral_professional | Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.1 CRITICAL
CVE-2026-42560 — auth: Patreon provider assigns the same local user ID to every authenticated Patreon acco…

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the …

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.6 HIGH
CVE-2026-42311 — Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e…

pillow | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.1 MEDIUM
CVE-2026-42310 — Pillow: PDF Parsing Trailer Infinite Loop (DoS)

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the…

pillow | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.1 MEDIUM
CVE-2026-42309 — Pillow: Heap buffer overflow with nested list coordinates

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polyg…

pillow | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.1 MEDIUM
CVE-2026-42308 — Pillow: Integer overflow when processing fonts

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer…

pillow | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2025-15634 — HCL BigFix WebUI is affected by a missing authorization vulnerability

A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2025-15633 — HCL BigFix WebUI is affected by an improper authorization vulnerability

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables)…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
Showing 20 of 5693 Results