Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 5,381 - 5,400 of 34,868 CVEs

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has b...

Product: Assimp
Published: May 31, 2026
Source: NVD
CVE-2026-48210 MEDIUM - 5.7

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the β€œIs visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue a...

Vendor: OTRS AG
Product: OTRS
Published: May 31, 2026
Source: NVD

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local acces...

Product: Assimp
Published: May 31, 2026
Source: NVD
CVE-2026-8796 HIGH - 8.1

Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_...

Published: May 31, 2026
Source: NVD
CVE-2026-10194 MEDIUM - 6.3

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotel...

Vendor: OFFIS
Product: DCMTK
Published: May 31, 2026
Source: NVD
CVE-2026-10193 MEDIUM - 6.3

A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql i...

Product: OFCMS
Published: May 31, 2026
Source: NVD
CVE-2026-10192 HIGH - 8.8

A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be us...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10191 HIGH - 8.8

A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly discl...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10190 MEDIUM - 6.5

A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The e...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10189 HIGH - 8.8

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to th...

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10188 HIGH - 8.8

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

Vendor: Tenda
Product: W12
Published: May 31, 2026
Source: NVD
CVE-2026-10187 CRITICAL - 9.8

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is pos...

Vendor: Totolink
Product: N300RH
Published: May 31, 2026
Source: NVD
CVE-2026-10186 HIGH - 7.3

A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit ha...

Vendor: code-projects
Product: Online Hospital Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10185 HIGH - 7.3

A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10184 HIGH - 7.3

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been rel...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: May 31, 2026
Source: NVD
CVE-2026-10183 HIGH - 8.8

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-10182 MEDIUM - 6.3

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attack can be launched remotely. The exploit has been publicly dis...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD
CVE-2026-49490 HIGH - 8.1

OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manip...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD
CVE-2026-49489 HIGH - 8.5

OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based...

Vendor: OpenCATS
Product: OpenCATS
Published: May 31, 2026
Source: NVD
CVE-2026-10181 HIGH - 8.8

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made publi...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 31, 2026
Source: NVD