Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,750
Quick preset (or use dates below)
Clear Filters
Showing 2,001 - 2,020 of 13,436 CVEs
CVE-2026-10155 MEDIUM - 4.7

A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate...

Vendor: Bdtask
Product: Multi-Store Inventory Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10154 MEDIUM - 4.3

A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to version 23.0.3 is sufficie...

Vendor: Dolibarr
Product: ERP CRM
Published: May 31, 2026
Source: NVD
CVE-2026-10153 MEDIUM - 4.3

A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is p...

Vendor: westboy
Product: CicadasCMS
Published: May 30, 2026
Source: NVD
CVE-2026-10152 MEDIUM - 6.3

A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack m...

Vendor: TaleLin
Product: lin-cms-spring-boot
Published: May 30, 2026
Source: NVD
CVE-2026-10127 MEDIUM - 6.3

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack may be initiated remotely. The exploit has be...

Vendor: Edimax
Product: BR-6478AC
Published: May 30, 2026
Source: NVD
CVE-2026-8594 MEDIUM - 6.2

Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just t...

Published: May 30, 2026
Source: NVD
CVE-2018-25423 MEDIUM - 6.2

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.

Vendor: Armcode
Product: Arm Whois
Published: May 30, 2026
Source: NVD
CVE-2018-25421 MEDIUM - 6.5

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile and traverse directories using ../ sequences to access sensitive ...

Vendor: Openstamanager
Product: Open STA Manager
Published: May 30, 2026
Source: NVD
CVE-2026-10117 MEDIUM - 4.3

A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been made available to the public and could...

Product: Open5GS
Published: May 30, 2026
Source: NVD
CVE-2026-10116 MEDIUM - 4.3

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of service. The attack may be initiated remotely. The ex...

Product: Open5GS
Published: May 30, 2026
Source: NVD
CVE-2026-10115 MEDIUM - 4.3

A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit is publicly available and might be used....

Product: Open5GS
Published: May 30, 2026
Source: NVD
CVE-2026-10114 MEDIUM - 4.3

A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. This manipulation causes out-of-bounds write. The attack can be initiated remotely. The exploit has been publ...

Product: Open5GS
Published: May 30, 2026
Source: NVD
CVE-2026-10113 MEDIUM - 4.3

A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. The manipulation results in denial of service. It is possible to launch the attack remotely. The exploit has b...

Product: Open5GS
Published: May 30, 2026
Source: NVD
CVE-2026-5071 MEDIUM - 6.1

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where assertions are disabled, a userspace application that...

Published: May 30, 2026
Source: NVD
CVE-2026-48840 MEDIUM - 5.3

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

Vendor: Exim
Product: Exim
Published: May 30, 2026
Source: NVD
CVE-2026-47408 MEDIUM - 6.5

praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47395 MEDIUM - 5.5

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-47390 MEDIUM - 5.5

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-9831 MEDIUM - 6.3

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue w...

Published: May 29, 2026
Source: NVD
CVE-2026-47268 MEDIUM - 6.4

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an authenticated Nezha dashboard user can create or update a DDNS profile with provider webhook and configure an arbitrary webhook_url, HTTP method, reque...

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 29, 2026
Source: GitHub