NVD CVEs — 本日公開 (13 件)
CVE-2026-18103 4.9 MEDIUM
A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containin
CVE-2026-18852 3.3 LOW
A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions.
CVE-2026-18853 5.3 MEDIUM
A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The exploit has been discl
CVE-2026-18854 7.3 HIGH
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of
CVE-2026-45705 5.3 MEDIUM
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near t
CVE-2026-45809
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a
CVE-2026-46334
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing th
CVE-2026-18856 4.7 MEDIUM
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The
CVE-2026-18859 7.3 HIGH
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used
CVE-2026-18895 8.8 HIGH
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been ma
GitHub Security Advisories — 本日公開 (20 件)
GHSA-74mg-chvx-67jh
HIGH
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted...
GHSA-r4f5-m256-cxv8
UNKNOWN
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows...
GHSA-5h56-28xw-5746
LOW
A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected...
GHSA-hqxv-537f-gq45
MEDIUM
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
GHSA-gpvf-48jp-phv5
HIGH
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function...
GHSA-26jj-c4g2-h8m6
LOW
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function...
GHSA-29v6-h4xg-jpwm
MEDIUM
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10...
GHSA-v276-wxc4-7v7p
LOW
A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18...
GHSA-pp2c-7vpq-xf5f
MEDIUM
Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows...
GHSA-4q74-w4p3-c8cx
LOW
A security vulnerability has been detected in RackTables up to 0.22.0...