Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33925
Total
2632
Critical
10022
High
10229
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-6025 | CRITICAL | 9.8 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of … | Apr 10, 2026 |
| CVE-2026-6024 | HIGH | 7.3 | A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path … | Apr 10, 2026 |
| CVE-2026-6016 | HIGH | 8.8 | A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. … | Apr 10, 2026 |
| CVE-2026-6015 | HIGH | 8.8 | A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such … | Apr 10, 2026 |
| CVE-2026-5477 | UNKNOWN | — | An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The function wc_CmacUpdate used the guard `if (cmac->totalSz … | Apr 10, 2026 |
| CVE-2026-6014 | HIGH | 8.8 | A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. … | Apr 10, 2026 |
| CVE-2026-6013 | HIGH | 8.8 | A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The … | Apr 10, 2026 |
| CVE-2026-6012 | HIGH | 8.8 | A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. … | Apr 10, 2026 |
| CVE-2026-6011 | MEDIUM | 5.6 | A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component … | Apr 10, 2026 |
| CVE-2026-4482 | UNKNOWN | — | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For … | Apr 10, 2026 |
| CVE-2026-6010 | MEDIUM | 6.3 | A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a … | Apr 10, 2026 |
| CVE-2026-6007 | MEDIUM | 6.3 | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname … | Apr 10, 2026 |
| CVE-2026-6006 | MEDIUM | 6.3 | A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation … | Apr 10, 2026 |
| CVE-2026-6005 | MEDIUM | 6.3 | A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a … | Apr 10, 2026 |
| CVE-2026-5501 | UNKNOWN | — | wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate … | Apr 10, 2026 |
| CVE-2026-5500 | UNKNOWN | — | wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac … | Apr 10, 2026 |
| CVE-2026-5479 | UNKNOWN | — | In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and related EVP cipher finalization functions) fails to verify the authentication tag before returning … | Apr 10, 2026 |
| CVE-2026-5466 | UNKNOWN | — | wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie in `[1, … | Apr 10, 2026 |
| CVE-2026-5188 | UNKNOWN | — | An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry … | Apr 10, 2026 |
| CVE-2026-2305 | MEDIUM | 6.4 | The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` post meta values in … | Apr 10, 2026 |
| CVE-2026-6004 | HIGH | 7.3 | A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the … | Apr 10, 2026 |
| CVE-2026-6003 | LOW | 2.4 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation … | Apr 10, 2026 |
| CVE-2026-6000 | MEDIUM | 4.3 | A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database … | Apr 10, 2026 |
| CVE-2026-5999 | MEDIUM | 6.3 | A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. … | Apr 10, 2026 |
| CVE-2026-33551 | LOW | 3.5 | An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using … | Apr 10, 2026 |