Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28297
Total
2180
Critical
8507
High
8806
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-32905 | HIGH | 8.3 | OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without … | May 29, 2026 |
| CVE-2026-10101 | MEDIUM | 6.3 | ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, … | May 29, 2026 |
| CVE-2026-10099 | MEDIUM | 4.0 | XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending unmasked … | May 29, 2026 |
| CVE-2026-10069 | HIGH | 7.5 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource … | May 29, 2026 |
| CVE-2026-10068 | HIGH | 7.3 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call … | May 29, 2026 |
| CVE-2026-10067 | HIGH | 8.8 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The … | May 29, 2026 |
| CVE-2026-10066 | HIGH | 8.8 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component … | May 29, 2026 |
| CVE-2026-10065 | HIGH | 8.8 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument … | May 29, 2026 |
| CVE-2026-10064 | MEDIUM | 6.3 | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument … | May 29, 2026 |
| CVE-2018-25404 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25403 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25402 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25401 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25400 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25399 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25398 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25397 | MEDIUM | 5.3 | PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated … | May 29, 2026 |
| CVE-2018-25396 | HIGH | 7.5 | Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request … | May 29, 2026 |
| CVE-2018-25395 | HIGH | 8.2 | Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter … | May 29, 2026 |
| CVE-2018-25394 | HIGH | 8.2 | Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter … | May 29, 2026 |
| CVE-2018-25393 | MEDIUM | 6.5 | Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. … | May 29, 2026 |
| CVE-2018-25392 | HIGH | 7.1 | MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters … | May 29, 2026 |
| CVE-2018-25391 | HIGH | 7.5 | HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that … | May 29, 2026 |
| CVE-2018-25390 | HIGH | 8.2 | HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter … | May 29, 2026 |
| CVE-2018-25389 | HIGH | 8.2 | HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter … | May 29, 2026 |