Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-10157 — Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication

A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation le…

open5gs | Remote | Authentication
May 31, 2026 May 31, 2026
May 31, 2026
May 31, 2026
4.3 MEDIUM
CVE-2026-10156 — Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption

A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulatio…

open5gs | Remote | Denial of Service
May 31, 2026 May 31, 2026
May 31, 2026
May 31, 2026
5.8 MEDIUM
CVE-2026-10155 — Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_repo…

A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accou…

May 31, 2026 May 31, 2026
May 31, 2026
May 31, 2026
5.3 MEDIUM
CVE-2026-10154 — Dolibarr ERP CRM messaging.php authorization

A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads …

erp_crm | Remote | Authorization
May 31, 2026 May 31, 2026
May 31, 2026
May 31, 2026
5.0 MEDIUM
CVE-2026-10153 — westboy CicadasCMS AbstractCacheManager.java search cross site scripting

A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. Th…

cicadascms | Remote | Cross-Site Scripting
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
6.5 MEDIUM
CVE-2026-10152 — TaleLin lin-cms-spring-boot book Endpoint BookController.java access control

A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.ja…

lin-cms-spring-boot | Remote | Authorization
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
6.5 MEDIUM
CVE-2026-10127 — Edimax BR-6478AC POST Request formStaDrvSetup command injection

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the …

br-6478ac_firmware | Remote | Injection
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
9.0 HIGH
CVE-2026-10126 — Edimax BR-6478AC POST Request formQoS buffer overflow

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the…

br-6478ac_firmware | Remote | Memory Corruption
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
0.0 NA
CVE-2026-8594 — Text::LineFold versions through 2019.001 for Perl duplicate the output based on the numbe…

Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line break characters (such…

| Denial of Service
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
9.0 HIGH
CVE-2026-10125 — Edimax BR-6478AC POST Request formPPPoESetup stack-based overflow

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The ma…

br-6478ac_firmware | Remote | Memory Corruption
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
9.0 HIGH
CVE-2026-10124 — Shibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflow

A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead t…

tomato | Remote | Memory Corruption
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
9.0 HIGH
CVE-2026-10123 — TRENDnet TEW-432BRP formSetDomainFilter stack-based overflow

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_doma…

tew-432brp | Remote | Memory Corruption
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
9.0 HIGH
CVE-2026-10122 — TRENDnet TEW-432BRP formSetProtocolFilter stack-based overflow

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_na…

tew-432brp | Remote | Memory Corruption
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
9.0 HIGH
CVE-2026-10121 — TRENDnet TEW-432BRP formSetUrlFilter stack-based overflow

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keywor…

tew-432brp | Remote | Memory Corruption
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
7.5 HIGH
CVE-2018-25426 — WinMTR 0.91 Denial of Service via Buffer Overflow

WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers c…

Remote | Denial of Service
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
8.2 HIGH
CVE-2018-25425 — Yot CMS 3.3.1 SQL Injection via aid and cid Parameters

Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers …

Remote | Injection
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
8.2 HIGH
CVE-2018-25424 — Gate Pass Management System 2.1 SQL Injection via login-exec.php

Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters.…

Remote | Injection
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
6.2 MEDIUM
CVE-2018-25423 — Arm Whois 3.11 Denial of Service via Buffer Overflow

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 byte…

| Denial of Service
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
8.2 HIGH
CVE-2018-25422 — MOGG web simulator Script All Version SQL Injection via play.php

MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attacke…

Remote | Injection
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
6.5 MEDIUM
CVE-2018-25421 — Open STA Manager 2.3 Arbitrary File Download via Path Traversal

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules…

Remote | Path Traversal
May 30, 2026 May 30, 2026
May 30, 2026
May 30, 2026
Showing 20 of 6701 Results