Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 5,321 - 5,340 of 34,822 CVEs
CVE-2026-10213 MEDIUM - 5.4

A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has bee...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10212 MEDIUM - 6.3

A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly avail...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10211 MEDIUM - 6.3

A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py. This manipulation causes incorrect authorization. It is possible to initiate the attack remotely. The exploit has been publicly...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10210 MEDIUM - 6.3

A vulnerability was found in AstrBotDevs AstrBot 4.23.6. Affected by this vulnerability is the function _sanitize_prompt_description of the file astrbot/core/skills/skill_manager.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and ...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10209 MEDIUM - 6.3

A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remo...

Vendor: code-projects
Product: Online Hospital Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10208 HIGH - 7.3

A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be us...

Vendor: code-projects
Product: Online Hospital Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10206 HIGH - 8.8

A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. Th...

Vendor: D-Link
Product: DI-8400
Published: Jun 01, 2026
Source: NVD
CVE-2026-10205 MEDIUM - 6.3

A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and m...

Vendor: Metasoft 美特软件
Product: MetaCRM
Published: Jun 01, 2026
Source: NVD
CVE-2026-10204 MEDIUM - 6.3

A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. This manipulation causes sql injection. The attack may be initiated re...

Product: OFCMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-10203 MEDIUM - 6.3

A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemParamController.java of the component JSON Query Interface. The manipulation results in sql injection. The attack can be launched rem...

Product: OFCMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-10202 MEDIUM - 6.3

A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipulation leads to sql injection. The attack can be initiated rem...

Product: OFCMS
Published: Jun 01, 2026
Source: NVD

A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects of the file FBXExporter.cpp of the component UV Channel Handler. Executing a manipulation can lead to divide by zero. The attack needs to be launched locally. The exploit has been ...

Product: Assimp
Published: Jun 01, 2026
Source: NVD
CVE-2026-10200 MEDIUM - 5.3

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been m...

Product: Assimp
Published: May 31, 2026
Source: NVD

A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out locally. The exploit has been disclosed to the publ...

Product: Assimp
Published: May 31, 2026
Source: NVD

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has b...

Product: Assimp
Published: May 31, 2026
Source: NVD
CVE-2026-48210 MEDIUM - 5.7

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue a...

Vendor: OTRS AG
Product: OTRS
Published: May 31, 2026
Source: NVD

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local acces...

Product: Assimp
Published: May 31, 2026
Source: NVD
CVE-2026-8796 HIGH - 8.1

Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_...

Published: May 31, 2026
Source: NVD
CVE-2026-10194 MEDIUM - 6.3

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotel...

Vendor: OFFIS
Product: DCMTK
Published: May 31, 2026
Source: NVD
CVE-2026-10193 MEDIUM - 6.3

A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql i...

Product: OFCMS
Published: May 31, 2026
Source: NVD