Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,949
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,341 - 5,360 of 34,822 CVEs
CVE-2026-10192 HIGH - 8.8

A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be us...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10191 HIGH - 8.8

A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly discl...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10190 MEDIUM - 6.5

A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The e...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10189 HIGH - 8.8

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to th...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10188 HIGH - 8.8

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10187 CRITICAL - 9.8

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is pos...

Vendor: Totolink
Product: N300RH
Published: May 31, 2026
Source: NVD
CVE-2026-10186 HIGH - 7.3

A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit ha...

Vendor: code-projects
Product: Online Hospital Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10185 HIGH - 7.3

A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10184 HIGH - 7.3

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been rel...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10183 HIGH - 8.8

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10182 MEDIUM - 6.3

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attack can be launched remotely. The exploit has been publicly dis...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-49490 HIGH - 8.1

OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manip...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD
CVE-2026-49489 HIGH - 8.5

OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD
CVE-2026-10181 HIGH - 8.8

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made publi...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10180 MEDIUM - 6.3

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may b...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10179 HIGH - 8.8

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the function formSetWlanEncrypt of the file /goform/formSetWlanEncrypt. This manipulation of the argument webpage causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publishe...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10178 HIGH - 7.3

A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be ...

Vendor: code-projects
Product: Online Music Site
Published: May 31, 2026
Source: NVD
CVE-2026-10177 MEDIUM - 6.3

A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has be...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10176 MEDIUM - 6.3

A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and coul...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10175 MEDIUM - 6.3

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been ...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD