Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,788
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 9,121 - 9,140 of 36,778 CVEs

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

Vendor: ZTE
Product: ZXUniPOS NDS-LTE
Published: May 26, 2026
Source: NVD
CVE-2026-39661 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.

Vendor: Magentech
Product: SW Core
Published: May 26, 2026
Source: NVD
CVE-2026-39642 MEDIUM - 5.3

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.

Vendor: SpabRice
Product: Nyla
Published: May 26, 2026
Source: NVD
CVE-2026-27427 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.

Vendor: Dylan Kuhn
Product: Geo Mashup
Published: May 26, 2026
Source: NVD
CVE-2026-25713 HIGH - 7.8

MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 26, 2026
Source: NVD
CVE-2026-25104 HIGH - 7.8

MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 26, 2026
Source: NVD
CVE-2026-24638 MEDIUM - 4.3

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

Vendor: Webful Creations
Product: RepairBuddy
Published: May 26, 2026
Source: NVD
CVE-2026-24590 MEDIUM - 5.3

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

Vendor: VideoWhisper.com
Product: Paid Videochat Turnkey Site
Published: May 26, 2026
Source: NVD
CVE-2026-8047 HIGH - 7.5

The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.

Published: May 26, 2026
Source: NVD
CVE-2026-8046 HIGH - 8.1

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.

Published: May 26, 2026
Source: NVD
CVE-2026-44469 HIGH - 7.8

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before insta...

Vendor: CODESYS
Product: CODESYS Development System
Published: May 26, 2026
Source: NVD
CVE-2026-44468 HIGH - 7.8

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary co...

Vendor: CODESYS
Product: CODESYS Development System
Published: May 26, 2026
Source: NVD
CVE-2026-39655 MEDIUM - 5.3

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

Vendor: TeconceTheme
Product: Mayosis Core
Published: May 26, 2026
Source: NVD
CVE-2026-9534 MEDIUM - 6.3

A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit...

Published: May 26, 2026
Source: NVD
CVE-2026-9533 MEDIUM - 6.3

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate th...

Published: May 26, 2026
Source: NVD
CVE-2026-9532 MEDIUM - 6.3

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed f...

Published: May 26, 2026
Source: NVD
CVE-2026-9496 HIGH - 7.5

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing exces...

Published: May 26, 2026
Source: NVD
CVE-2026-9495 HIGH - 7.3

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attack...

Published: May 26, 2026
Source: NVD
CVE-2026-3314 MEDIUM - 4.6

Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This is...

Published: May 26, 2026
Source: NVD
CVE-2026-9531 MEDIUM - 6.3

A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The ex...

Published: May 26, 2026
Source: NVD