| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | Wavlink | NU516U1 | Medium | 6.3 | 2026-05-09 16:15:09 | Deep Dive |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | Wavlink | NU516U1 | Medium | 6.3 | 2026-05-09 15:15:10 | Deep Dive |
| CVE-2026-8198 | Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - Unauthenticated Information Disclosure via REST API | logtivity | Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity | Medium | 5.3 | 2026-05-09 12:29:18 | Deep Dive |
| CVE-2026-8186 | Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds | - | Open5GS | Medium | 5.3 | 2026-05-09 12:00:16 | Deep Dive |
| CVE-2026-8187 | Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumption | - | Open5GS | Medium | 5.3 | 2026-05-09 10:58:27 | Deep Dive |
| CVE-2026-8185 | UGREEN CM933 Administrative missing authentication | UGREEN | CM933 | Medium | 6.3 | 2026-05-09 10:15:09 | Deep Dive |
| CVE-2026-32683 | 海康萤石App历史版本API接口网络监听漏洞 | EZVIZ | EZVIZ APP | Medium | 5.3 | 2026-05-09 08:29:10 | Deep Dive |
| CVE-2026-3828 | 海康威视交换机存在认证远程命令执行漏洞 | Hikvision | DS-3E1310P-SI | High | 7.2 | 2026-05-09 08:27:56 | Deep Dive |
| CVE-2026-1749 | 海康威视HikCentral Professional未授权获取管理员权限漏洞 | Hikvision | HikCentral Professional | Medium | 6.8 | 2026-05-09 08:27:16 | Deep Dive |
| CVE-2025-15634 | HCL BigFix WebUI is affected by a missing authorization vulnerability | HCLSoftware | BigFix WebUI | - | - | 2026-05-09 05:05:34 | Deep Dive |
| CVE-2025-15633 | HCL BigFix WebUI is affected by an improper authorization vulnerability | HCLSoftware | BigFix WebUI | - | - | 2026-05-09 04:58:55 | Deep Dive |
| CVE-2026-42560 | auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation | go-pkgz | auth | Critical | 9.1 | 2026-05-09 04:15:01 | Deep Dive |
| CVE-2026-42311 | Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) | python-pillow | Pillow | - | - | 2026-05-09 04:11:58 | Deep Dive |
| CVE-2026-42310 | Pillow: PDF Parsing Trailer Infinite Loop (DoS) | python-pillow | Pillow | - | - | 2026-05-09 04:10:48 | Deep Dive |
| CVE-2026-42308 | Pillow: Integer overflow when processing fonts | python-pillow | Pillow | - | - | 2026-05-09 04:09:02 | Deep Dive |
| CVE-2026-42309 | Pillow: Heap buffer overflow with nested list coordinates | python-pillow | Pillow | - | - | 2026-05-09 04:08:11 | Deep Dive |
| CVE-2026-41311 | LiquidJS is vulnerable to Denial of Service via circular block reference in layout | harttle | liquidjs | High | 7.5 | 2026-05-09 04:03:25 | Deep Dive |
| CVE-2026-42301 | Improper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2spec | befeleme | pyp2spec | High | 7.8 | 2026-05-09 03:59:35 | Deep Dive |
| CVE-2026-41163 | bubblewrap vulnerable to privilege escalation in setuid mode via ptrace | containers | bubblewrap | - | - | 2026-05-09 03:56:52 | Deep Dive |
| CVE-2026-42296 | Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure | argoproj | argo-workflows | High | 8.1 | 2026-05-09 03:52:03 | Deep Dive |