Total CVEs

133,033

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,070
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 29,438 CVEs
CVE-2026-10127 MEDIUM - 6.3

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack may be initiated remotely. The exploit has be...

Vendor: Edimax
Product: BR-6478AC
Published: May 30, 2026
Source: NVD
CVE-2026-10126 HIGH - 8.8

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has be...

Vendor: Edimax
Product: BR-6478AC
Published: May 30, 2026
Source: NVD

Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just t...

Published: May 30, 2026
Source: NVD
CVE-2026-10125 HIGH - 8.8

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initia...

Vendor: Edimax
Product: BR-6478AC
Published: May 30, 2026
Source: NVD
CVE-2026-10124 HIGH - 8.8

A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been pub...

Vendor: Shibby
Product: Tomato
Published: May 30, 2026
Source: NVD
CVE-2026-10123 HIGH - 8.8

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow....

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 30, 2026
Source: NVD
CVE-2026-10122 HIGH - 8.8

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has bee...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 30, 2026
Source: NVD
CVE-2026-10121 HIGH - 8.8

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit ...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 30, 2026
Source: NVD
CVE-2018-25426 HIGH - 7.5

WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers can create a specially crafted input file with 238 bytes of data to trigger a buffer overflow conditio...

Vendor: Winmtr
Product: WinMTR
Published: May 30, 2026
Source: NVD
CVE-2018-25425 HIGH - 8.2

Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php with crafted SQL payloads in the aid or cid parameters to extract ...

Vendor: Yot
Product: Yot CMS
Published: May 30, 2026
Source: NVD
CVE-2018-25424 HIGH - 8.2

Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form par...

Vendor: Livebms
Product: Gate Pass Management System
Published: May 30, 2026
Source: NVD
CVE-2018-25423 MEDIUM - 6.2

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.

Vendor: Armcode
Product: Arm Whois
Published: May 30, 2026
Source: NVD
CVE-2018-25422 HIGH - 8.2

MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php with crafted SQL payloads in the id parameter to extract sensiti...

Vendor: spider312
Product: MOGG web simulator Script
Published: May 30, 2026
Source: NVD
CVE-2018-25421 MEDIUM - 6.5

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile and traverse directories using ../ sequences to access sensitive ...

Vendor: Openstamanager
Product: Open STA Manager
Published: May 30, 2026
Source: NVD
CVE-2018-25420 HIGH - 8.2

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with crafted SQL payloads to extract sensitive database in...

Vendor: Aiopmsd
Product: AiOPMSD Final
Published: May 30, 2026
Source: NVD
CVE-2018-25419 HIGH - 8.2

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with crafted SQL payloads in the genre parameter to extract sensiti...

Vendor: Aiopmsd
Product: AiOPMSD Final
Published: May 30, 2026
Source: NVD
CVE-2018-25418 HIGH - 8.2

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with crafted SQL payloads in the year parameter to extract sensitive ...

Vendor: Aiopmsd
Product: AiOPMSD Final
Published: May 30, 2026
Source: NVD
CVE-2018-25417 HIGH - 8.2

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract s...

Vendor: Aiopmsd
Product: AiOPMSD Final
Published: May 30, 2026
Source: NVD
CVE-2018-25416 HIGH - 8.2

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract s...

Vendor: Aiopmsd
Product: AiOPMSD Final
Published: May 30, 2026
Source: NVD
CVE-2018-25415 HIGH - 8.2

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extrac...

Vendor: Aiopmsd
Product: AiOPMSD Final
Published: May 30, 2026
Source: NVD