Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,941 - 2,960 of 12,512 CVEs
CVE-2018-25364 HIGH - 8.2

Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, ...

Vendor: Fyffe
Product: PHP-Twitter-Clone
Published: May 25, 2026
Source: NVD
CVE-2018-25362 HIGH - 8.2

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information includin...

Vendor: Fyffe
Product: PHP-Twitter-Clone
Published: May 25, 2026
Source: NVD
CVE-2018-25360 HIGH - 8.4

AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions ...

Vendor: Agatasoft
Product: Auto PingMaster
Published: May 25, 2026
Source: NVD
CVE-2018-25359 HIGH - 8.4

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable...

Vendor: Splinterware
Product: Splinterware System Scheduler Pro
Published: May 25, 2026
Source: NVD
CVE-2026-9461 HIGH - 8.8

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly an...

Published: May 25, 2026
Source: NVD
CVE-2026-9460 HIGH - 8.8

A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made availabl...

Published: May 25, 2026
Source: NVD
CVE-2026-9459 HIGH - 8.8

A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely....

Published: May 25, 2026
Source: NVD
CVE-2026-9453 HIGH - 7.3

A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The ...

Published: May 25, 2026
Source: NVD
CVE-2026-9452 HIGH - 7.3

A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit...

Published: May 25, 2026
Source: NVD
CVE-2026-9447 HIGH - 7.3

A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Name results in sql injection. The attack is possible to be carried out remotely. The exploit has been ...

Published: May 25, 2026
Source: NVD
CVE-2026-9443 HIGH - 8.8

A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remo...

Published: May 25, 2026
Source: NVD
CVE-2026-9442 HIGH - 8.8

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The e...

Published: May 25, 2026
Source: NVD
CVE-2026-45361 HIGH - 8.1

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-pr...

Vendor: Apache Software Foundation
Product: Apache Airflow Google provider
Published: May 25, 2026
Source: NVD
CVE-2026-9431 HIGH - 8.8

A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the function fromPptpUserAdd of the file /goform/PptpUserAdd. The manipulation of the argument opttype leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be ...

Published: May 25, 2026
Source: NVD
CVE-2026-9430 HIGH - 8.8

A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the function formGstDhcpSetSer of the file /goform/GstDhcpSetSerof. Executing a manipulation of the argument dips can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit ...

Published: May 25, 2026
Source: NVD
CVE-2026-9429 HIGH - 8.8

A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. Performing a manipulation of the argument delno results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit ...

Published: May 25, 2026
Source: NVD
CVE-2026-9428 HIGH - 8.8

A vulnerability has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromPPTPUserSetting of the file /goform/PPTPUserSetting. Such manipulation of the argument delno leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the ...

Published: May 25, 2026
Source: NVD
CVE-2026-25193 HIGH - 8.1

Insertion of Sensitive Information into Log File (CWE-532)Β in some Command Centre Service installers could lead to Service Account credentials exposure.β€― Mitigating Factor:Β Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are pot...

Published: May 25, 2026
Source: NVD
CVE-2026-9427 HIGH - 8.8

A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component webs. This manipulation of the argument selSSID/submit-url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The expl...

Published: May 25, 2026
Source: NVD
CVE-2026-9426 HIGH - 8.8

A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url results in stack-based buffer overfl...

Published: May 25, 2026
Source: NVD