Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2021-47922 — WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS

Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScrip…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.4 MEDIUM
CVE-2021-47910 — WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS

AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon titl…

accesspress_social_icons | Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.4 MEDIUM
CVE-2021-47907 — Rocket LMS 1.1 Persistent Cross-Site Scripting via Support Tickets

Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attac…

rocket_lms | Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8244 — Industrial Application Software IAS Canias ERP Login RMI improper authentication

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVe…

Remote | Authentication
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.9 MEDIUM
CVE-2026-8243 — Industrial Application Software IAS Canias ERP JNLP Deployment Endpoint hard-coded key

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to…

Remote | Cryptography
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
3.7 LOW
CVE-2026-8242 — Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results…

Remote | Information Disclosure
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8241 — Industrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authori…

A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation lea…

Remote | Authorization
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8235 — 8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulatio…

| Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
9.0 HIGH
CVE-2026-8234 — EFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflow

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument se…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
2.9 LOW
CVE-2026-45186 — Apache libexpat XML Denial of Service

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

libexpat | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
4.6 MEDIUM
CVE-2026-8233 — Dotouch XproUPF access control

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of com…

| Authorization
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.1 MEDIUM
CVE-2026-8232 — Dotouch XproUPF UPF Process libvlib.so vlib_worker_loop denial of service

A vulnerability was found in Dotouch XproUPF 2.0.0-release-088aa7c4. This impacts the function vlib_worker_loop in the library /usr/xpro/upf/tools/libs/libvlib.so of the component UPF Process. The ma…

| Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8231 — CodeAstro Online Catering Ordering System deleteorder.php sql injection

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql inject…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-7263 — DoS attack via DOMNode::C14N()

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML docu…

php | Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-6104 — Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectl…

php | Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8230 — Wavlink NU516U1 login.cgi sys_login1 os command injection

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8229 — Wavlink NU516U1 wireless.cgi WifiBasic os command injection

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypTy…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8228 — Wavlink NU516U1 wireless.cgi advance os command injection

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8227 — Wavlink NU516U1 adm.cgi wzdapMesh os command injection

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be init…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8226 — Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in…

open5gs | Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
Showing 20 of 5471 Results