Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,949
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,361 - 5,380 of 34,822 CVEs
CVE-2026-10174 MEDIUM - 6.3

A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism failure. The attack may be launched remotely. The exploit is ...

Vendor: Aider-AI
Product: Aider
Published: May 31, 2026
Source: NVD
CVE-2026-10173 MEDIUM - 4.3

A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate...

Vendor: Orthanc
Product: Explorer 2
Published: May 31, 2026
Source: NVD
CVE-2026-10172 MEDIUM - 6.3

A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted u...

Vendor: Bdtask
Product: Multi-Store Inventory Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10171 MEDIUM - 4.7

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and ...

Vendor: code-projects
Product: Online Music Site
Published: May 31, 2026
Source: NVD
CVE-2026-10170 MEDIUM - 6.3

A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been published and may be u...

Vendor: code-projects
Product: Visitor Management System
Published: May 31, 2026
Source: NVD

A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The m...

Vendor: OUSL-GROUP-BrinaryBrains
Product: School Student Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10168 MEDIUM - 6.3

A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to improper control of...

Vendor: OUSL-GROUP-BrinaryBrains
Product: School Student Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10167 HIGH - 7.3

A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file application/controllers/Login.php of the component MY_Controller. Executing a manipulation of the argumen...

Vendor: OUSL-GROUP-BrinaryBrains
Product: School Student Management System
Published: May 31, 2026
Source: NVD
CVE-2026-8382 MEDIUM - 5.3

The Advanced Custom Fields (ACFยฎ) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite...

Published: May 31, 2026
Source: NVD
CVE-2026-10166 MEDIUM - 6.3

A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. Th...

Vendor: Edimax
Product: BR-6478AC
Published: May 31, 2026
Source: NVD
CVE-2026-10165 HIGH - 8.8

A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack may be performed...

Vendor: Edimax
Product: BR-6478AC
Published: May 31, 2026
Source: NVD
CVE-2026-10164 HIGH - 8.8

A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulation of the argument ShareName/SelectName results in buffer overflow. The attack can be executed remotely. The exploit has b...

Vendor: Edimax
Product: BR-6478AC
Published: May 31, 2026
Source: NVD
CVE-2026-10163 HIGH - 8.8

A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. The manipulation of the argument UserName/Password leads to buffer overflow. Remote exploitation of the attack is possible...

Vendor: Edimax
Product: BR-6478AC
Published: May 31, 2026
Source: NVD
CVE-2026-10162 HIGH - 8.8

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publi...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10161 HIGH - 8.8

A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument status_statistic results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is no...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10160 HIGH - 8.8

A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. Such manipulation of the argument start_wizard leads to stack-based buffer overflow. The attack can be launched remotely. The...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10159 HIGH - 8.8

A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSysLog of the file /goform/formSysLog. This manipulation of the argument current_page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10158 HIGH - 8.8

A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10157 HIGH - 7.3

A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is public...

Product: Open5GS
Published: May 31, 2026
Source: NVD
CVE-2026-10156 MEDIUM - 4.3

A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulation of the argument nf_info_pool can lead to resource consumption. The attack may be performed from rem...

Product: Open5GS
Published: May 31, 2026
Source: NVD