<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Buffer Overflow (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/buffer.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/buffer-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Buffer Overflow (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:28 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-35085 – A remote attacker with user privileges can exploit a stack buffer overflow in gd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35085</guid>
    <pubDate>Wed, 03 Jun 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35085</strong></p>
  <p>A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35084 – A remote attacker with user privileges can exploit a stack buffer overflow in da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35084</guid>
    <pubDate>Wed, 03 Jun 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35084</strong></p>
  <p>A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35083 – A remote attacker with user privileges can exploit a stack buffer overflow to ga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35083</guid>
    <pubDate>Wed, 03 Jun 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35083</strong></p>
  <p>A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-50031 – ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-50031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50031</guid>
    <pubDate>Wed, 03 Jun 2026 04:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-50031</strong></p>
  <p>ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors comm…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4478 – Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4478</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4478</strong></p>
  <p>Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1871 – TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1871</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1871</strong></p>
  <p>TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request.  Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition.  This…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30652 – A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi end...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30652</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30652</strong></p>
  <p>A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30650 – A post-authentication remote buffer overflow vulnerability exists in the /cgi-bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30650</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30650</strong></p>
  <p>A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30649 – Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30649</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30649</strong></p>
  <p>Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25277 – Memory corruption while using Strongbox due to buffer overflow.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25277</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25277</strong></p>
  <p>Memory corruption while using Strongbox due to buffer overflow.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10293 – A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10293</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10293</strong></p>
  <p>A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the argument Profile causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10292 – A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10292</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10292</strong></p>
  <p>A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0100 – In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0100</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0100</strong></p>
  <p>In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0059 – In multiple functions of sdp_discovery.cc, there is a possible way to achieve co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0059</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0059</strong></p>
  <p>In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25432 – Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25432</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25432</strong></p>
  <p>Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25427 – Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25427</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25427</strong></p>
  <p>Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception handler and gain command execution when the application processes the input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43958 – A flaw was found in rrdcached, a component of rrdtool. A local attacker with acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43958</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43958</strong></p>
  <p>A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43623 – microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43623</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43623</strong></p>
  <p>microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a crafted TAR archive with non-null-terminated name or linkname fields. The function uses strcpy() to copy 100-byte ustar format fields that lack null terminators, causing writes of up to 355 bytes into a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10270 – A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10270</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10270</strong></p>
  <p>A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10259 – A security vulnerability has been detected in H3C Magic B0 up to 100R002. The af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10259</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10259</strong></p>
  <p>A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did no…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0826 – In certain scenarios when the admin has enabled Interactive Connectivity Establi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0826</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0826</strong></p>
  <p>In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable                remote code execution on Poly Voice products on the Linux platform.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20452 – In wlan AP driver, there is a possible memory corruption due to a heap buffer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20452</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20452</strong></p>
  <p>In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10206 – A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10206</guid>
    <pubDate>Mon, 01 Jun 2026 01:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10206</strong></p>
  <p>A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The initial researcher advisory mentions contradicting parameter names to be affected.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10192 – A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10192</guid>
    <pubDate>Sun, 31 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10192</strong></p>
  <p>A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10191 – A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10191</guid>
    <pubDate>Sun, 31 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10191</strong></p>
  <p>A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10189 – A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10189</guid>
    <pubDate>Sun, 31 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10189</strong></p>
  <p>A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10188 – A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10188</guid>
    <pubDate>Sun, 31 May 2026 15:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10188</strong></p>
  <p>A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-10187 – A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10187</guid>
    <pubDate>Sun, 31 May 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-10187</strong></p>
  <p>A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10183 – A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10183</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10183</strong></p>
  <p>A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10181 – A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10181</guid>
    <pubDate>Sun, 31 May 2026 13:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10181</strong></p>
  <p>A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10179 – A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10179</guid>
    <pubDate>Sun, 31 May 2026 11:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10179</strong></p>
  <p>A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the function formSetWlanEncrypt of the file /goform/formSetWlanEncrypt. This manipulation of the argument webpage causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As th…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10165 – A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10165</guid>
    <pubDate>Sun, 31 May 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10165</strong></p>
  <p>A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10164 – A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10164</guid>
    <pubDate>Sun, 31 May 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10164</strong></p>
  <p>A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulation of the argument ShareName/SelectName results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10163 – A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10163</guid>
    <pubDate>Sun, 31 May 2026 04:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10163</strong></p>
  <p>A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. The manipulation of the argument UserName/Password leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10162 – A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10162</guid>
    <pubDate>Sun, 31 May 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10162</strong></p>
  <p>A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10161 – A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10161</guid>
    <pubDate>Sun, 31 May 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10161</strong></p>
  <p>A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument status_statistic results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009)…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10160 – A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10160</guid>
    <pubDate>Sun, 31 May 2026 03:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10160</strong></p>
  <p>A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. Such manipulation of the argument start_wizard leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor explains: "This product has been E…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10159 – A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10159</guid>
    <pubDate>Sun, 31 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10159</strong></p>
  <p>A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSysLog of the file /goform/formSysLog. This manipulation of the argument current_page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor explains: "This product has been…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10158 – A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10158</guid>
    <pubDate>Sun, 31 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10158</strong></p>
  <p>A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "This product has been EOL for 15 year…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10126 – A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10126</guid>
    <pubDate>Sat, 30 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10126</strong></p>
  <p>A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10125 – A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10125</guid>
    <pubDate>Sat, 30 May 2026 16:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10125</strong></p>
  <p>A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10124 – A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the func...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10124</guid>
    <pubDate>Sat, 30 May 2026 16:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10124</strong></p>
  <p>A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. This vulnerability…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10123 – A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10123</guid>
    <pubDate>Sat, 30 May 2026 16:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10123</strong></p>
  <p>A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10122 – A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10122</guid>
    <pubDate>Sat, 30 May 2026 16:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10122</strong></p>
  <p>A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 y…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10121 – A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10121</guid>
    <pubDate>Sat, 30 May 2026 16:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10121</strong></p>
  <p>A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25426 – WinMTR 0.91 contains a denial of service vulnerability that allows attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25426</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25426</strong></p>
  <p>WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers can create a specially crafted input file with 238 bytes of data to trigger a buffer overflow condition that causes the application to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10120 – A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected elemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10120</guid>
    <pubDate>Sat, 30 May 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10120</strong></p>
  <p>A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009)…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10119 – A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10119</guid>
    <pubDate>Sat, 30 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10119</strong></p>
  <p>A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor explains: "This product has been EOL for 15 ye…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10067 – A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10067</guid>
    <pubDate>Fri, 29 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10067</strong></p>
  <p>A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10066 – A security vulnerability has been detected in Shibby Tomato up to 1.28. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10066</guid>
    <pubDate>Fri, 29 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10066</strong></p>
  <p>A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10065 – A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10065</guid>
    <pubDate>Fri, 29 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10065</strong></p>
  <p>A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25383 – Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25383</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25383</strong></p>
  <p>Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded through the Convert function, enabling execution of arbitrary code through ROP chain gadgets and shellcode injection.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10063 – A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10063</guid>
    <pubDate>Fri, 29 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10063</strong></p>
  <p>A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10062 – A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10062</guid>
    <pubDate>Fri, 29 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10062</strong></p>
  <p>A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "This product has been…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9940 – Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9940</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9940</strong></p>
  <p>Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9939 – Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9939</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9939</strong></p>
  <p>Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9926 – Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9926</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9926</strong></p>
  <p>Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9924 – Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.21...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9924</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9924</strong></p>
  <p>Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9915 – Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9915</guid>
    <pubDate>Thu, 28 May 2026 23:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9915</strong></p>
  <p>Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9038 – A stack-based buffer overflow vulnerability in the charging controller’s signal-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9038</guid>
    <pubDate>Thu, 28 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9038</strong></p>
  <p>A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49127 – Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49127</guid>
    <pubDate>Thu, 28 May 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49127</strong></p>
  <p>Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries in…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41565 – CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41565</guid>
    <pubDate>Thu, 28 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41565</strong></p>
  <p>CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers.  The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the bu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46149 – In the Linux kernel, the following vulnerability has been resolved:

scsi: targe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46149</guid>
    <pubDate>Thu, 28 May 2026 10:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46149</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()  target_tg_pt_gp_members_show() formats LUN paths with snprintf() into a 256-byte stack buffer, then will memcpy() cur_len bytes from that buffer.  snprintf() returns the length the output would have had, which can exceed the buffer size when the fabric W…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46123 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46123</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46123</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: virtio_bt: clamp rx length before skb_put  virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we posted to the device. The RX skb is allocated in virtbt_add_inbuf() and exposed to virtio as exactly 1000 bytes via sg_init_one().  Checking len…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8363 – A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8363</guid>
    <pubDate>Wed, 27 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8363</strong></p>
  <p>A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8362 – A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8362</guid>
    <pubDate>Wed, 27 May 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8362</strong></p>
  <p>A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70103 – Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70103</guid>
    <pubDate>Wed, 27 May 2026 15:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70103</strong></p>
  <p>Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8179 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8179</guid>
    <pubDate>Wed, 27 May 2026 14:17:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8179</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8175 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8175</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8175</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45935 – In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45935</guid>
    <pubDate>Wed, 27 May 2026 14:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45935</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot  In the 'DeleteIndexEntryRoot' case of the 'do_action' function, the entry size ('esize') is retrieved from the log record without adequate bounds checking.  Specifically, the code calculates the end of the entry ('e2') using:     e2 = Add2Ptr(e1, esize);  It then cal…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45878 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45878</guid>
    <pubDate>Wed, 27 May 2026 14:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45878</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Fix watch_id bounds checking in debug address watch v2  The address watch clear code receives watch_id as an unsigned value (u32), but some helper functions were using a signed int and checked bits by shifting with watch_id.  If a very large watch_id is passed from userspace, it can be converted to a negative value.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38427 – An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38427</guid>
    <pubDate>Wed, 27 May 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38427</strong></p>
  <p>An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored in a uint16_t variable; values above 65535 wrap around, causing allocation of a smaller buffer than the data actually read.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38426 – Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38426</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38426</strong></p>
  <p>Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() function.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38422 – Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38422</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38422</strong></p>
  <p>Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() function.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12686 – Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12686</guid>
    <pubDate>Wed, 27 May 2026 09:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12686</strong></p>
  <p>Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9632 – A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9632</guid>
    <pubDate>Wed, 27 May 2026 02:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9632</strong></p>
  <p>A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9631 – A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9631</guid>
    <pubDate>Wed, 27 May 2026 02:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9631</strong></p>
  <p>A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9628 – A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9628</guid>
    <pubDate>Wed, 27 May 2026 02:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9628</strong></p>
  <p>A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9627 – A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9627</guid>
    <pubDate>Wed, 27 May 2026 02:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9627</strong></p>
  <p>A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49014 – In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49014</guid>
    <pubDate>Wed, 27 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49014</strong></p>
  <p>In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. Thi…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9605 – A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9605</guid>
    <pubDate>Wed, 27 May 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9605</strong></p>
  <p>A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended acti…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44983 – smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44983</guid>
    <pubDate>Tue, 26 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44983</strong></p>
  <p>smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring unsafe code from the caller. This vulnerability is fixed in 2.6.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48689 – FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48689</guid>
    <pubDate>Tue, 26 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48689</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form 'if (offset + length > maximum_internal_storage_size + 1)' instea…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8834 – IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8834</guid>
    <pubDate>Tue, 26 May 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8834</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24192 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24192</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24192</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48864 – A flaw was found in libsolv. This heap buffer overflow occurs during the decompr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48864</guid>
    <pubDate>Tue, 26 May 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48864</strong></p>
  <p>A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of progr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48691 – FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48691</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48691</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(uint32_t)' and stores it in a uint8_t field (line 600-605). Since uint8_t can only hold values 0-255, an AS_…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48686 – FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48686</guid>
    <pubDate>Tue, 26 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48686</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in src/bgp_protocol.cpp reads prefix_bit_length directly from the BGP packet (line 99) without validating it is <= 32 for IPv4 prefixes. This value is passed to how_much_bytes_we_need_for_storing_cert…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25713 – MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25713</guid>
    <pubDate>Tue, 26 May 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25713</strong></p>
  <p>MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25104 – MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25104</guid>
    <pubDate>Tue, 26 May 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25104</strong></p>
  <p>MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8376 – Perl versions through 5.43.10 have a heap buffer overflow when compiling regular...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8376</guid>
    <pubDate>Tue, 26 May 2026 00:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8376</strong></p>
  <p>Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvG…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-680</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9482 – A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9482</guid>
    <pubDate>Mon, 25 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9482</strong></p>
  <p>A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9481 – A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9481</guid>
    <pubDate>Mon, 25 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9481</strong></p>
  <p>A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9480 – A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9480</guid>
    <pubDate>Mon, 25 May 2026 19:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9480</strong></p>
  <p>A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9479 – A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9479</guid>
    <pubDate>Mon, 25 May 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9479</strong></p>
  <p>A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did n…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9463 – A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9463</guid>
    <pubDate>Mon, 25 May 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9463</strong></p>
  <p>A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9462 – A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9462</guid>
    <pubDate>Mon, 25 May 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9462</strong></p>
  <p>A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25377 – Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25377</guid>
    <pubDate>Mon, 25 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25377</strong></p>
  <p>Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog to trigger a reverse shell with system privileges.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25376 – Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25376</guid>
    <pubDate>Mon, 25 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25376</strong></p>
  <p>Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft malicious input in the Registration Name and Registration Key fields to overwrite the SEH chain and execute shellcode for reverse shell access.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25375 – SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25375</guid>
    <pubDate>Mon, 25 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25375</strong></p>
  <p>SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious input in the Registration Name and Registration Key fields to trigger a stack-based buffer overflow and execute a reverse shell payload.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25375">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
