Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,555
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,101 - 2,120 of 28,420 CVEs
CVE-2026-8776 HIGH - 8.8

A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotel...

Published: May 18, 2026
Source: NVD
CVE-2026-8775 HIGH - 8.8

A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been...

Published: May 18, 2026
Source: NVD
CVE-2026-8774 MEDIUM - 6.3

A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack may be performed from remote. The exploit is now public and...

Published: May 18, 2026
Source: NVD
CVE-2026-8773 MEDIUM - 4.7

A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/p...

Published: May 18, 2026
Source: NVD
CVE-2026-8772 MEDIUM - 4.7

A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks...

Published: May 18, 2026
Source: NVD
CVE-2026-8771 HIGH - 7.3

A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exp...

Published: May 18, 2026
Source: NVD
CVE-2026-8770 LOW - 3.3

A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON-RPC Server. Such manipulation of the argument dirPath leads to path traversal. An attack has to be approached locally. The expl...

Vendor: continue
Product: continue
Published: May 18, 2026
Source: NVD
CVE-2026-8769 MEDIUM - 4.3

A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The atta...

Vendor: vercel
Product: ai
Published: May 17, 2026
Source: NVD
CVE-2026-8768 HIGH - 7.3

A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The ex...

Vendor: vercel
Product: ai
Published: May 17, 2026
Source: NVD
CVE-2026-8767 MEDIUM - 5.0

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an att...

Vendor: vercel
Product: ai
Published: May 17, 2026
Source: NVD
CVE-2026-8766 MEDIUM - 4.3

A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possi...

Vendor: kilo
Product: kilo_code
Published: May 17, 2026
Source: NVD
CVE-2026-8765 MEDIUM - 4.3

A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is...

Vendor: kilo
Product: kilo_code
Published: May 17, 2026
Source: NVD
CVE-2026-8764 HIGH - 7.2

A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may ...

Published: May 17, 2026
Source: NVD
CVE-2026-8721 CRITICAL - 9.8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on t...

Published: May 17, 2026
Source: NVD
CVE-2026-8507 CRITICAL - 9.8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution pote...

Published: May 17, 2026
Source: NVD
CVE-2026-46720 HIGH - 8.2

Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Vendor: RRWO
Product: Net::Statsd::Tiny
Published: May 17, 2026
Source: NVD
CVE-2026-8759 HIGH - 7.3

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special e...

Published: May 17, 2026
Source: NVD
CVE-2026-8758 HIGH - 7.3

A vulnerability was determined in Metasoft ηΎŽη‰Ήθ½―δ»Ά MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclose...

Published: May 17, 2026
Source: NVD
CVE-2026-8757 HIGH - 7.3

A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has ...

Vendor: adenhq
Product: hive
Published: May 17, 2026
Source: NVD
CVE-2026-8756 HIGH - 7.3

A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_config of the file webui_preprocess.py of the component Gradio Interface. Such manipulation of the argument data_dir leads to path traversal. The attac...

Published: May 17, 2026
Source: NVD