Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 30 May 2026

RSS

477 vulnerabilities published on 30 May 2026

Severity:
Delta Sql 1.8.2 allows malicious file uploads
CVE-2018-25412
An attacker can upload any type of file, including malicious PHP files, to Delta Sql's server. This could allow the attacker to execute their own code on the server, potentially leading to unauthorize...
9.3
Edimax BR-6478AC: Unsecured Configuration May Cause Remote Attack
CVE-2026-10126
A security flaw in Edimax BR-6478AC version 1.23 allows an attacker to remotely launch a malicious attack. This is because the device's configuration settings are not properly secured. To protect your...
7.4
Edimax BR-6478AC 1.23: Remote Code Execution via User Input
CVE-2026-10125
The Edimax BR-6478AC router has a vulnerability that can allow hackers to execute code remotely. This is a serious issue because it could be exploited by anyone with the right tools, potentially givin...
7.4
Shibby Tomato 1.28 Zserv Handler IPv4 Overflow
CVE-2026-10124
A security flaw in Shibby Tomato's Zserv Handler allows an attacker to execute malicious code remotely, potentially disrupting your network. This issue affects older, unsupported versions of Shibby To...
7.4
TRENDnet TEW-432BRP: Remote attack possible through router settings
CVE-2026-10123
A security risk was found in a very old version of the TRENDnet TEW-432BRP router software. This means that a remote attacker could potentially access and manipulate the router's settings. Since this ...
7.4
TRENDnet TEW-432BRP 3.10B20: Remote Attack via Misused Network Setting
CVE-2026-10122
A security flaw in an older version of TRENDnet's TEW-432BRP wireless router's settings could allow an attacker to remotely exploit the device. This issue affects devices that are no longer supported ...
7.4
TRENDnet TEW-432BRP: Remote Code Execution via Buffer Overflow
CVE-2026-10121
An old version of the TRENDnet TEW-432BRP router has a security flaw that can be exploited by hackers to execute malicious code remotely. This affects a very old model that is no longer supported by t...
7.4
SIM-PKH 2.4.1 allows attackers to upload malicious PHP files
CVE-2018-25409
Authenticated attackers can upload malicious PHP files through the SIM-PKH 2.4.1 system, which can lead to unauthorized code execution. This is a serious security risk that can allow attackers to take...
8.7
TRENDnet Router Firewall Rule Manipulation Allows Remote Attack
CVE-2026-10120
A security flaw in an old version of the TRENDnet TEW-432BRP router's firewall settings can be exploited remotely. This issue only affects routers that are no longer supported by the manufacturer. Sin...
7.4
TRENDnet TEW-432BRP: Malicious Code Can Crash Router
CVE-2026-10119
An old version of TRENDnet's router software has a security weakness that could allow hackers to crash the device. This is a concern because it's an old product that no longer receives security update...
7.4
WordPress Spectra Gutenberg Blocks plugin allows hackers to run server code
CVE-2026-7465
An attacker with contributor-level access can execute server code on WordPress sites using the Spectra Gutenberg Blocks plugin. This can happen if a malicious user embeds two specific blocks of conten...
8.8
Apache HTTP Server: mod_proxy_ajp security update
RLSA-2026:21391
Apache HTTP Server's mod_proxy_ajp module has several security issues that could allow hackers to access or crash your server, potentially leading to data breaches or server downtime. It's recommended...
8.2
Yot CMS 3.3.1 allows unauthorized database access
CVE-2018-25425
The Yot CMS 3.3.1 software has a security flaw that lets hackers access your database without a password. This means they can potentially see sensitive information about your website, such as database...
8.8
Gate Pass Management System 2.1: Unauthenticated Access through Login
CVE-2018-25424
An attacker can submit fake login information to gain access to the Gate Pass Management System without a valid username and password. This is a serious issue because it allows unauthorized access to ...
8.8
MOGG web simulator SQL Injection: Unauthenticated Access to Database
CVE-2018-25422
The MOGG web simulator is vulnerable to SQL injection attacks. This means that attackers can access sensitive information in the database, such as usernames, without needing a password. To protect aga...
8.8
AiOPMSD Final 1.0.0 SQL Injection Risk: Unauthorized Data Exposure
CVE-2018-25420
The AiOPMSD software version 1.0.0 is at risk because attackers can access sensitive information without permission. This is a serious issue because it allows attackers to extract confidential databas...
8.8
AiOPMSD Final 1.0.0 Genre Parameter SQL Injection
CVE-2018-25419
The genre parameter in AiOPMSD Final 1.0.0 allows attackers to extract sensitive database information, including usernames, database names, and version details. This is a serious security risk because...
8.8
AiOPMSD Final 1.0.0: Unauthenticated SQL Injection via Year Parameter
CVE-2018-25418
The AiOPMSD Final 1.0.0 software has a security flaw that allows attackers to access sensitive information without needing a password. This can happen if an attacker sends a special request to the sof...
8.8
AiOPMSD Final 1.0.0 allows unauthorized access to database info
CVE-2018-25417
An attacker can use a specially crafted URL to access sensitive database information, including usernames and database versions, without needing a password. This could allow an attacker to gather info...
8.8
AiOPMSD Final 1.0.0 SQL Injection Risk: Unauthenticated Access to Sensitive Data
CVE-2018-25416
The AiOPMSD Final 1.0.0 software has a security weakness that allows unauthorized users to access sensitive database information, including usernames and database details, by manipulating a specific i...
8.8
AiOPMSD Final 1.0.0 SQL injection risk through director parameter
CVE-2018-25415
AiOPMSD Final 1.0.0 has a security weakness that lets hackers access sensitive information without needing a login. This can happen if a hacker sends a special kind of request to the director.php page...
8.8
AiOPMSD Final 1.0.0: Unauthenticated SQL Code Injection via Actor Parameter
CVE-2018-25414
The AiOPMSD Final 1.0.0 software is at risk of unauthorized access to sensitive database information. This means attackers can potentially steal usernames, database names, and other details without ne...
8.8
AiOPMSD Final 1.0.0 SQL Injection Risk: Unauthorized Data Exposure
CVE-2018-25413
AiOPMSD Final 1.0.0 has a security issue that allows attackers to access sensitive information without permission. This means that attackers can potentially see usernames, database names, and other im...
8.8
MGB OpenSource Guestbook SQL Injection Risk: Data Exposure
CVE-2018-25411
MGB OpenSource Guestbook's guestbook feature has a security flaw that allows attackers to access sensitive information. This could lead to unauthorized access to database information, including table ...
8.8
eNdonesia Portal 8.7 allows database information theft
CVE-2018-25407
eNdonesia Portal 8.7 has a security weakness that lets attackers steal sensitive database information without needing a password. This means they could learn usernames, database names, and other detai...
8.8