VulnSea

Daily digest

Saturday 30 May 2026

22 new CVEs this day, in line with the recent average. Severity skewed high: 19 high, 86% of the total. One arrived with exploitation evidence or public exploit code already attached.

22
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2026-46242High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-10125High· 8.8
4mo ago

A vulnerability was identified in Edimax BR-6478AC 1.23

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-10124High· 8.8
4mo ago

A vulnerability was determined in Shibby Tomato up to 1.28

A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is p…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10123High· 8.8
4mo ago

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_lis…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10122High· 8.8
4mo ago

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflo…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10121High· 8.8
4mo ago

A flaw has been found in TRENDnet TEW-432BRP 3.10B20

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. …

▾ TwilightEPSS 0.45%via NVD
CVE-2018-25425High· 8.2
4mo ago

Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters

Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php wit…

▾ TwilightEPSS 0.27%via NVD
CVE-2018-25424High· 8.2
4mo ago

Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters

Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST req…

▾ TwilightEPSS 0.32%via NVD
CVE-2018-25422High· 8.2
4mo ago

MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter

MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php w…

▾ TwilightEPSS 0.26%via NVD
CVE-2018-25420High· 8.2
4mo ago

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with …

▾ TwilightEPSS 0.27%via NVD
CVE-2018-25419High· 8.2
4mo ago

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with…

▾ TwilightEPSS 0.27%via NVD
CVE-2018-25418High· 8.2
4mo ago

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with c…

▾ TwilightEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.