Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,750
Quick preset (or use dates below)
Clear Filters
Showing 1,981 - 2,000 of 13,436 CVEs
CVE-2026-10202 MEDIUM - 6.3

A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipulation leads to sql injection. The attack can be initiated rem...

Product: OFCMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-10200 MEDIUM - 5.3

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been m...

Product: Assimp
Published: May 31, 2026
Source: NVD
CVE-2026-48210 MEDIUM - 5.7

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue a...

Vendor: OTRS AG
Product: OTRS
Published: May 31, 2026
Source: NVD
CVE-2026-10194 MEDIUM - 6.3

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotel...

Vendor: OFFIS
Product: DCMTK
Published: May 31, 2026
Source: NVD
CVE-2026-10193 MEDIUM - 6.3

A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql i...

Product: OFCMS
Published: May 31, 2026
Source: NVD
CVE-2026-10190 MEDIUM - 6.5

A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The e...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10182 MEDIUM - 6.3

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attack can be launched remotely. The exploit has been publicly dis...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10180 MEDIUM - 6.3

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may b...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10177 MEDIUM - 6.3

A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has be...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10176 MEDIUM - 6.3

A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and coul...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10175 MEDIUM - 6.3

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been ...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10174 MEDIUM - 6.3

A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism failure. The attack may be launched remotely. The exploit is ...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10173 MEDIUM - 4.3

A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate...

Vendor: Orthanc
Product: Explorer 2
Published: May 31, 2026
Source: NVD
CVE-2026-10172 MEDIUM - 6.3

A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted u...

Vendor: Bdtask
Product: Multi-Store Inventory Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10171 MEDIUM - 4.7

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and ...

Vendor: code-projects
Product: Online Music Site
Published: May 31, 2026
Source: NVD
CVE-2026-10170 MEDIUM - 6.3

A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been published and may be u...

Vendor: code-projects
Product: Visitor Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10168 MEDIUM - 6.3

A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to improper control of...

Vendor: OUSL-GROUP-BrinaryBrains
Product: School Student Management System
Published: May 31, 2026
Source: NVD
CVE-2026-8382 MEDIUM - 5.3

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite...

Published: May 31, 2026
Source: NVD
CVE-2026-10166 MEDIUM - 6.3

A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. Th...

Vendor: Edimax
Product: BR-6478AC
Published: May 31, 2026
Source: NVD
CVE-2026-10156 MEDIUM - 4.3

A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulation of the argument nf_info_pool can lead to resource consumption. The attack may be performed from rem...

Product: Open5GS
Published: May 31, 2026
Source: NVD