Total CVEs

133,059

Critical Severity

2,915

High Severity

10,581

Last 7 Days

2,048
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,141 - 3,160 of 29,464 CVEs
CVE-2026-8781 MEDIUM - 4.3

A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfiguration of the file ngap/handler.go. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may b...

Published: May 18, 2026
Source: NVD
CVE-2026-8780 MEDIUM - 4.3

A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP Message Handler. The manipulation leads to memory corruption. The attack may be initiated remotely. The exploit is publicly available a...

Published: May 18, 2026
Source: NVD
CVE-2026-8779 MEDIUM - 4.3

A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit has been publicly discl...

Published: May 18, 2026
Source: NVD
CVE-2026-8777 MEDIUM - 6.3

A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Performing a manipulation of the argument stadrv_ssid results in command injection. The attack can be initiated remotely. The...

Published: May 18, 2026
Source: NVD
CVE-2026-8776 HIGH - 8.8

A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotel...

Published: May 18, 2026
Source: NVD
CVE-2026-8775 HIGH - 8.8

A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been...

Published: May 18, 2026
Source: NVD
CVE-2026-8774 MEDIUM - 6.3

A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack may be performed from remote. The exploit is now public and...

Published: May 18, 2026
Source: NVD
CVE-2026-8773 MEDIUM - 4.7

A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/p...

Published: May 18, 2026
Source: NVD
CVE-2026-8772 MEDIUM - 4.7

A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks...

Published: May 18, 2026
Source: NVD
CVE-2026-8771 HIGH - 7.3

A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exp...

Published: May 18, 2026
Source: NVD
CVE-2026-8770 LOW - 3.3

A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON-RPC Server. Such manipulation of the argument dirPath leads to path traversal. An attack has to be approached locally. The expl...

Vendor: continue
Product: continue
Published: May 18, 2026
Source: NVD
CVE-2026-8769 MEDIUM - 4.3

A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The atta...

Vendor: vercel
Product: ai
Published: May 17, 2026
Source: NVD
CVE-2026-8768 HIGH - 7.3

A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The ex...

Vendor: vercel
Product: ai
Published: May 17, 2026
Source: NVD
CVE-2026-8767 MEDIUM - 5.0

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an att...

Vendor: vercel
Product: ai
Published: May 17, 2026
Source: NVD
CVE-2026-8766 MEDIUM - 4.3

A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possi...

Vendor: kilo
Product: kilo_code
Published: May 17, 2026
Source: NVD
CVE-2026-8765 MEDIUM - 4.3

A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is...

Vendor: kilo
Product: kilo_code
Published: May 17, 2026
Source: NVD
CVE-2026-8764 HIGH - 7.2

A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may ...

Published: May 17, 2026
Source: NVD
CVE-2026-8721 CRITICAL - 9.8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on t...

Published: May 17, 2026
Source: NVD
CVE-2026-8507 CRITICAL - 9.8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution pote...

Published: May 17, 2026
Source: NVD
CVE-2026-46720 HIGH - 8.2

Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Vendor: RRWO
Product: Net::Statsd::Tiny
Published: May 17, 2026
Source: NVD