VulnSea

Daily digest

Sunday 10 May 2026

32 new CVEs this day, in line with the recent average. Of those, 1 critical and 4 high. open5gs was the most-affected vendor with 9.

32
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 32 published.

CVE-2026-6722Critical· 9.8⚖ disputed
4mo ago

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their referenc…

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their referenc…

▾ Midnightphp · phpEPSS 1.3%via NVD
CVE-2026-8234High· 8.8
4mo ago

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer …

▾ TwilightEPSS 0.80%via NVD
CVE-2026-8177High· 7.5
4mo ago

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read…

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.88%via NVD
CVE-2026-7568High· 7.5
4mo ago

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string.…

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string.…

▾ Twilightphp · phpEPSS 0.84%via NVD
CVE-2026-7262High· 7.5
4mo ago

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missin…

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missin…

▾ Twilightphp · phpEPSS 1.0%via NVD
CVE-2026-8230Medium· 6.3
4mo ago

A flaw has been found in Wavlink NU516U1 240425

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8229Medium· 6.3
4mo ago

A vulnerability was detected in Wavlink NU516U1 240425

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Re…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8228Medium· 6.3
4mo ago

A security vulnerability has been detected in Wavlink NU516U1 240425

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command inject…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8227Medium· 6.3
4mo ago

A weakness has been identified in Wavlink NU516U1 240425

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been m…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8231Medium· 6.3
4mo ago

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…

▾ SunlitEPSS 0.32%via NVD
CVE-2022-50945Medium· 6.4
4mo ago

WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields

WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScrip…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-8235Medium· 5.5
4mo ago

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The…

▾ SunlitEPSS 3.6%via NVD

Most-affected vendors

By CVEs published in the period.