Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 24 May 2026
RSS91 vulnerabilities published on 24 May 2026
Severity:
Totolink A8000RU Web Management Interface DDNS Injection
CVE-2026-9404
The Totolink A8000RU's web management interface has a security flaw that allows an attacker to inject malicious commands remotely. This means an attacker can potentially take control of the device. It...
8.9
Totolink A8000RU Web Interface Command Injection Risk
CVE-2026-9388
The Totolink A8000RU's web interface has a security flaw that allows an attacker to inject malicious commands, potentially allowing them to access and control the router remotely. This could lead to u...
8.9
Totolink A8000RU Web Management Interface Allows Remote Code Execution
CVE-2026-9387
A security flaw in the Totolink A8000RU's web management interface could allow an attacker to take control of the router remotely. This is a serious issue because an attacker could use it to change se...
8.9
Totolink A8000RU Web Management Interface Language Setting Vulnerability
CVE-2026-9386
A hacker can remotely inject malicious commands into the Totolink A8000RU router's web management interface by manipulating the language setting. This could allow an attacker to take control of the ro...
8.9
Totolink A8000RU Web Interface Traceroute Settings Misuse
CVE-2026-9385
A vulnerability in the Totolink A8000RU's web interface allows an attacker to inject malicious commands, potentially giving them control over the device. This could lead to unauthorized changes or dis...
8.9
Totolink A8000RU Web Management Interface Allows Remote Code Execution
CVE-2026-9384
The Totolink A8000RU's web management interface has a security flaw that could allow an attacker to remotely take control of the device by sending a malicious request. This means an attacker could pot...
8.9
Wine registers itself as a handler for Windows executable files
DEBIAN-CVE-2026-48831
Wine incorrectly handles Windows executable files in some cases, potentially allowing malicious code to escape restricted environments. This is a concern because it could compromise the security of sy...
8.9
Edimax BR-6675nD Router: Remote Buffer Overflow
CVE-2026-9403
A vulnerability in the Edimax BR-6675nD router's software (version 1.12) allows an attacker to remotely take control of the device by sending a specific type of request. This could potentially lead to...
7.4
Edimax BR-6675nD 1.12: Remote Code Execution via Unsecured Function
CVE-2026-9401
A security issue in the Edimax BR-6675nD 1.12 router allows an attacker to execute malicious code remotely by manipulating a specific setting. This could potentially allow unauthorized access to the r...
7.4
Edimax BR-6675nD: Remote Buffer Overflow in POST Request Handler
CVE-2026-9399
A security flaw in the Edimax BR-6675nD's POST Request Handler can be exploited remotely, allowing an attacker to potentially crash the device or execute malicious code. This issue affects devices run...
7.4
H3C Magic B0: Remote buffer overflow in 5G SSID settings
CVE-2026-9393
A security flaw in H3C Magic B0's 5G SSID settings allows an attacker to potentially take control of the device remotely. This vulnerability was made public, but the vendor has not responded to addres...
7.4
Tenda F456 Router: Remote Buffer Overflow Risk
CVE-2026-9389
A vulnerability in the Tenda F456 router's software (version 1.0.0.5) allows an attacker to remotely exploit a buffer overflow, potentially causing the device to crash or become compromised. This coul...
7.4
Edimax BR-6675nD: Remote Buffer Overflow in PPTP Setup
CVE-2026-9382
The Edimax BR-6675nD router's PPTP setup feature has a security flaw that can be exploited remotely. This means an attacker could potentially take control of the router by sending a malicious request....
7.4
Edimax BR-6675nD: Remote Buffer Overflow Risk
CVE-2026-9381
A security flaw exists in the Edimax BR-6675nD router's PPPoE setup feature, allowing an attacker to potentially execute malicious code remotely. This issue affects all users who have not updated thei...
7.4
Edimax BR-6675nD Router: Remote Attack via L2TP Configuration
CVE-2026-9380
A security flaw in the Edimax BR-6675nD router's configuration feature allows an attacker to remotely take control of the device. This can happen if an attacker sends a specially crafted message to th...
7.4
Edimax EW-7438RPn: Remote Buffer Overflow Risk
CVE-2026-9360
A security flaw in the Edimax EW-7438RPn router's POST Request Handler can be exploited remotely, potentially allowing an attacker to execute malicious code. This issue has been publicly disclosed and...
7.4
Edimax EW-7438RPn Router: Remote Attack Possible
CVE-2026-9348
An unknown function in the Edimax EW-7438RPn router's web interface can be exploited remotely, potentially allowing an attacker to take control of the device. This issue affects routers with firmware ...
7.4
Edimax EW-7438RPn: Remote Buffer Overflow Risk
CVE-2026-9346
A security flaw in Edimax EW-7438RPn wireless routers up to version 1.31 could allow an attacker to execute malicious code from a distance. This could potentially disrupt or take control of the router...
7.4
Edimax EW-7438RPn: Remote Code Execution via Buffer Overflow
CVE-2026-9345
A security flaw in Edimax EW-7438RPn routers (up to version 1.31) allows hackers to remotely execute malicious code, potentially taking control of the router. This is a serious issue because it can be...
7.4
Edimax EW-7438RPn Router: Remote WPS Pin Code Overflow
CVE-2026-9344
A vulnerability in the Edimax EW-7438RPn router's WPS feature allows an attacker to remotely access the router's settings. This could potentially lead to unauthorized changes or even a complete takeov...
7.4
Prefect 3.6.18: GitHub Integration Git Command Injection Risk
CVE-2026-3515
An attacker can inject malicious commands into the GitHub integration in Prefect 3.6.18, potentially leading to server-side attacks, credential theft, or code execution. This issue only affects the Gi...
8.5
Besen BS20 EV Charging Station: Unauthorized Update Access
CVE-2026-9397
A security weakness has been found in the Besen BS20 EV Charging Station's ability to install software updates remotely. This means an attacker could potentially access the charging station's update s...
8.2
HuggingFace Transformers Library: Malicious Model Download and Execution
CVE-2026-4372
A severe vulnerability in the HuggingFace Transformers library allows attackers to download and execute malicious code on a user's system without their knowledge. This can happen when using the librar...
7.8
GNU SASL DIGEST-MD5 NULL Pointer Dereference
CVE-2026-48829
A vulnerability in GNU SASL's DIGEST-MD5 authentication could allow an attacker to crash the system. This issue affects both clients and servers using GNU SASL. To protect against this, update to GNU ...
7.5
Debian Linux: Unauthenticated Remote Code Execution via HTTP
DEBIAN-CVE-2026-48829
A security flaw in Debian Linux's httpd server allows hackers to run malicious code on a server without needing a password. This could lead to unauthorized access and data theft. Update to the latest ...
7.5