Total CVEs

138,170

Critical Severity

3,538

High Severity

12,685

Last 7 Days

1,967
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,061 - 2,080 of 12,382 CVEs
CVE-2026-10220 HIGH - 7.3

A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and ...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 01, 2026
Source: NVD
CVE-2026-10219 HIGH - 7.3

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The...

Vendor: nextlevelbuilder
Product: GoClaw
Published: Jun 01, 2026
Source: NVD
CVE-2026-10214 HIGH - 7.3

A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit h...

Vendor: zhayujie
Product: chatgpt-on-wechat
Published: Jun 01, 2026
Source: NVD
CVE-2026-10208 HIGH - 7.3

A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be us...

Vendor: code-projects
Product: Online Hospital Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10206 HIGH - 8.8

A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. Th...

Vendor: D-Link
Product: DI-8400
Published: Jun 01, 2026
Source: NVD
CVE-2026-8796 HIGH - 8.1

Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_...

Published: May 31, 2026
Source: NVD
CVE-2026-10192 HIGH - 8.8

A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be us...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10191 HIGH - 8.8

A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly discl...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10189 HIGH - 8.8

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to th...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10188 HIGH - 8.8

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10186 HIGH - 7.3

A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit ha...

Vendor: code-projects
Product: Online Hospital Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10185 HIGH - 7.3

A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10184 HIGH - 7.3

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been rel...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10183 HIGH - 8.8

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-49490 HIGH - 8.1

OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manip...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD
CVE-2026-49489 HIGH - 8.5

OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD
CVE-2026-10181 HIGH - 8.8

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made publi...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10179 HIGH - 8.8

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the function formSetWlanEncrypt of the file /goform/formSetWlanEncrypt. This manipulation of the argument webpage causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publishe...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10178 HIGH - 7.3

A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be ...

Vendor: code-projects
Product: Online Music Site
Published: May 31, 2026
Source: NVD
CVE-2026-10167 HIGH - 7.3

A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file application/controllers/Login.php of the component MY_Controller. Executing a manipulation of the argumen...

Vendor: OUSL-GROUP-BrinaryBrains
Product: School Student Management System
Published: May 31, 2026
Source: NVD