📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Technology/Software CRITICAL 1h Global malware Social Media and Consumer Technology HIGH 2h Global botnet Information Technology and IoT HIGH 2h Global vulnerability Enterprise Security, Software Development CRITICAL 3h Global vulnerability Software Development, Artificial Intelligence HIGH 3h Global apt Defense and Military CRITICAL 3h Global vulnerability Networking, Software, Infrastructure HIGH 3h Global phishing Information Technology HIGH 4h Global ransomware Multiple sectors CRITICAL 4h Global malware Multiple sectors CRITICAL 4h Global vulnerability Technology/Software CRITICAL 1h Global malware Social Media and Consumer Technology HIGH 2h Global botnet Information Technology and IoT HIGH 2h Global vulnerability Enterprise Security, Software Development CRITICAL 3h Global vulnerability Software Development, Artificial Intelligence HIGH 3h Global apt Defense and Military CRITICAL 3h Global vulnerability Networking, Software, Infrastructure HIGH 3h Global phishing Information Technology HIGH 4h Global ransomware Multiple sectors CRITICAL 4h Global malware Multiple sectors CRITICAL 4h Global vulnerability Technology/Software CRITICAL 1h Global malware Social Media and Consumer Technology HIGH 2h Global botnet Information Technology and IoT HIGH 2h Global vulnerability Enterprise Security, Software Development CRITICAL 3h Global vulnerability Software Development, Artificial Intelligence HIGH 3h Global apt Defense and Military CRITICAL 3h Global vulnerability Networking, Software, Infrastructure HIGH 3h Global phishing Information Technology HIGH 4h Global ransomware Multiple sectors CRITICAL 4h Global malware Multiple sectors CRITICAL 4h
📅 Daily Security Digest — Sunday, May 31, 2026

🇸🇦 Saudi Cyber Daily Digest

All security vulnerabilities, threats, and news aggregated today from trusted sources — continuously updated

Sunday, May 31, 2026 Today
67 CVEs
2 Threats
0 News
🛡 Security Vulnerabilities (CVE)
67 vulnerabilities
CVE-2026-10183
TRENDnet TEW-432BRP Stack Buffer Overflow in WLAN Setup Function
03:16 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly …
CVE-2026-10191
A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin
15:48 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has…
CVE-2026-10192
A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the
15:48 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly avail…
CVE-2026-10179
TRENDnet TEW-432BRP Stack-Based Buffer Overflow in WLAN Configuration
20:00 KSA
HIGH CVSS 8.8 CWE-119
A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the function formSetWlanEncrypt of the file /goform/formSetWlanEncrypt. This manipulation of the argument webpage causes stack-based buffer overflow. It is possible to initiate the attack remotely. The explo…
CVE-2026-10189
Tenda W12 3.0.0.7(4763) Stack-Based Buffer Overflow in cgiSysTimeInfoSet
15:07 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has …
CVE-2026-44832
Snipe-IT Privilege Escalation via Incomplete Permission Validation
15:16 KSA
HIGH CVSS 8.8 CWE-281
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the supe…
CVE-2026-10181
TRENDnet TEW-432BRP Stack Buffer Overflow in formSysCmd Function
03:16 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit…
CVE-2026-46368
Command Injection in luci-app-https-dns-proxy setInitAction Function
03:16 KSA
HIGH CVSS 8.8 CWE-77
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An auth…
CVE-2026-10188
Tenda W12 3.0.0.7(4763) Stack-Based Buffer Overflow in cgistaKickOff
15:07 KSA
HIGH CVSS 8.8 CWE-119
A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and m…
CVE-2026-10165
Edimax BR-6478AC Stack Buffer Overflow in WAN Configuration
03:16 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to stack-based buffer overflow. The att…
CVE-2026-10164
Edimax BR-6478AC Buffer Overflow in USB Folder Sharing Function
03:16 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulation of the argument ShareName/SelectName results in buffer overflow. The attack can be executed remotel…
CVE-2026-10163
Edimax BR-6478AC Buffer Overflow in USB Account Handler (CVE-2026-10163)
03:16 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. The manipulation of the argument UserName/Password leads to buffer overflow. Remote exploitation of th…
CVE-2026-10162
TRENDnet TEW-432BRP Stack Buffer Overflow in Password Function
03:16 KSA
HIGH CVSS 8.8 CWE-119
A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack may be launched remotely. The ex…
CVE-2026-10161
TRENDnet TEW-432BRP Stack Buffer Overflow in formResetStatistic
03:16 KSA
HIGH CVSS 8.8 CWE-119
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. This affects the function formResetStatistic of the file /goform/formResetStatistic. Performing a manipulation of the argument status_statistic results in stack-based buffer overflow. The attack may be initiated remotel…
CVE-2026-10160
TRENDnet TEW-432BRP Stack Buffer Overflow in formSetEnableWizard
03:16 KSA
HIGH CVSS 8.8 CWE-119
A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. Such manipulation of the argument start_wizard leads to stack-based buffer overflow. The attack can be la…
CVE-2026-10159
TRENDnet TEW-432BRP Stack Buffer Overflow in Syslog Function
03:16 KSA
HIGH CVSS 8.8 CWE-119
A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSysLog of the file /goform/formSysLog. This manipulation of the argument current_page causes stack-based buffer overflow. The attack can be initiated remotely. The ex…
CVE-2026-10158
TRENDnet TEW-432BRP Stack Buffer Overflow in Port Forwarding Function
03:16 KSA
HIGH CVSS 8.8 CWE-119
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. Affected is the function formPortFw of the file /goform/formPortFw. The manipulation of the argument server_name results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit h…
CVE-2026-45298
Dozzle SSRF via Unauthenticated Webhook Test Endpoint
21:16 KSA
HIGH CVSS 8.6 CWE-918
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a Web…
CVE-2026-49489
OpenCATS SQL Injection in sortDirection Parameter (CVE-2026-49489)
03:16 KSA
HIGH CVSS 8.5 CWE-89
OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php t…
CVE-2026-4480
Samba Printing Subsystem Shell Metacharacter Injection Remote Code Execution
03:16 KSA
HIGH CVSS 8.5 CWE-78
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this …
CVE-2026-44728
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel
09:06 KSA
HIGH CVSS 8.2 CWE-94
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed …
CVE-2026-48694
FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr
09:06 KSA
HIGH CVSS 8.1 CWE-77
FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is directly interpolated into Juniper NETCONF set-co…
CVE-2026-48695
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra
09:06 KSA
HIGH CVSS 8.1 CWE-78
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter di…
CVE-2026-48692
FastNetMon Unauthenticated gRPC API Allows DDoS Mitigation Bypass
03:16 KSA
HIGH CVSS 8.1 CWE-306
FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment explicitly acknowledges 'Listen on the giv…
CVE-2026-49490
OpenCATS SQL Injection in DataGrid Filter Handling (CVE-2026-49490)
03:16 KSA
HIGH CVSS 8.1 CWE-89
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable r…
CVE-2026-8834
IBM HTTP Server Buffer Overflow in Administration Server (CVE-2026-8834)
15:16 KSA
HIGH CVSS 8.0 CWE-122
IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.
CVE-2026-7452
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
09:06 KSA
HIGH CVSS 7.8 CWE-120
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2026-7454
Autodesk 3ds Max WRL File Memory Corruption RCE Vulnerability
15:16 KSA
HIGH CVSS 7.8 CWE-120
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2026-9560
OpenVPN Connect macOS Privilege Escalation via Background Service IPC
15:16 KSA
HIGH CVSS 7.8 CWE-78
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
CVE-2026-7451
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A
09:06 KSA
HIGH CVSS 7.8 CWE-787
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVE-2026-40384
Path Traversal in com_media API Search Parameter Validation
03:16 KSA
HIGH CVSS 7.5 CWE-22
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
CVE-2026-48688
FastNetMon BGP IPv6 MP_REACH_NLRI Out-of-Bounds Read Vulnerability
03:16 KSA
HIGH CVSS 7.5 CWE-125
FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks …
CVE-2026-8854
IBM HTTP Server mod_mem_cache Denial of Service Vulnerability
15:16 KSA
HIGH CVSS 7.5 CWE-825
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
CVE-2026-48896
Insufficient State Validation Allows 2FA Bypass
03:16 KSA
HIGH CVSS 7.5 CWE-287
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48897
2FA Bypass via Insufficient State Validation (CVE-2026-48897)
03:16 KSA
HIGH CVSS 7.5 CWE-287
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-8850
IBM HTTP Server mod_ibm_upload Denial of Service Vulnerability
09:06 KSA
HIGH CVSS 7.5 CWE-476
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
CVE-2026-8620
IBM WebSphere HTTP Request Smuggling Vulnerability (CVE-2026-8620)
15:16 KSA
HIGH CVSS 7.5 CWE-444
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.
CVE-2026-48697
FastNetMon TLS Certificate Verification Bypass in HTTPS Connections
03:16 KSA
HIGH CVSS 7.4 CWE-295
FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA ce…
CVE-2026-9550
Acrel EEMS Path Traversal Vulnerability in File Upload Endpoint
03:16 KSA
HIGH CVSS 7.3 CWE-22
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead t…
CVE-2026-9551
SQL Injection in Das Parking Management System 6.2.0 API Endpoint
03:16 KSA
HIGH CVSS 7.3 CWE-74
A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to init…
CVE-2026-9552
SQL Injection in Das Parking Management System 6.2.0 Search API
03:16 KSA
HIGH CVSS 7.3 CWE-74
A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exp…
CVE-2026-8835
IBM HTTP Server 8.5/9.0 Invalid Pointer Dereference Vulnerability
15:16 KSA
HIGH CVSS 7.3 CWE-822
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.
CVE-2026-9574
SQL Injection in itsourcecode Student Transcript Processing System 1.0
21:16 KSA
HIGH CVSS 7.3 CWE-74
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remot…
CVE-2026-9575
SQL Injection in itsourcecode Student Transcript System Admin Module
21:16 KSA
HIGH CVSS 7.3 CWE-74
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remote…
CVE-2026-9580
JeecgBoot LoginController Improper Access Control Vulnerability
21:16 KSA
HIGH CVSS 7.3 CWE-266
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicl…
CVE-2026-10167
A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee0
03:16 KSA
HIGH CVSS 7.3 CWE-287
A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file application/controllers/Login.php of the component MY_Controller. Executing a manipul…
CVE-2026-10186
SQL Injection in Online Hospital Management System 1.0 /patient.php
15:07 KSA
HIGH CVSS 7.3 CWE-74
A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remo…
CVE-2026-10185
SQL Injection in SourceCodester Hospitals Patient Records Management System 1.0
15:07 KSA
HIGH CVSS 7.3 CWE-74
A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The e…
CVE-2026-10184
SQL Injection in SourceCodester Hospital Patient Records Management System
15:07 KSA
HIGH CVSS 7.3 CWE-74
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The …
CVE-2026-10178
A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file
20:00 KSA
HIGH CVSS 7.3 CWE-74
A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is no…
CVE-2026-48690
FastNetMon Integer Overflow in Packet Buffer Allocation (CVE-2026-48690)
03:16 KSA
HIGH CVSS 7.1 CWE-122
FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(f…
CVE-2026-10190
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /b
00:00 KSA
MEDIUM CVSS 6.5 CWE-404
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the at…
CVE-2026-10152
A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of t
05:16 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access co…
CVE-2026-10166
A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /g
11:48 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carr…
CVE-2026-10168
A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad11
11:48 KSA
MEDIUM CVSS 6.3 CWE-99
A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to…
CVE-2026-10170
A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionali
13:32 KSA
MEDIUM CVSS 6.3 CWE-74
A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been pu…
CVE-2026-10172
A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the f
16:00 KSA
MEDIUM CVSS 6.3 CWE-284
A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module resul…
CVE-2026-10174
A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of th
16:00 KSA
MEDIUM CVSS 6.3 CWE-693
A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism failure. The attack may be launched remot…
CVE-2026-10175
A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_code
16:00 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. T…
CVE-2026-10176
A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the com
17:48 KSA
MEDIUM CVSS 6.3 CWE-74
A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to…
CVE-2026-10177
A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file
17:48 KSA
MEDIUM CVSS 6.3 CWE-918
A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely…
CVE-2026-10180
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/f
19:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to …
CVE-2026-10182
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the
21:18 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attack can be launched remotely. The exploit h…
CVE-2026-10193
A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-a
00:00 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.qu…
CVE-2026-10194
A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::dele
00:00 KSA
MEDIUM CVSS 6.3 CWE-119
A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may…
CVE-2026-8382
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
11:48 KSA
MEDIUM CVSS 5.3 CWE-862
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated at…
CVE-2026-10200
A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFComm
07:54 KSA
MEDIUM CVSS 5.3 CWE-119
A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. Th…
⚠️ Threat Intelligence
2 threats
rss:BleepingComputer
20:37 KSA
CRITICAL vulnerability
WP Maps Pro bug exploited to create admin accounts on WordPress sites Attackers are exploiting a critical vulnerability in the WP Maps Pro WordPress plugin that allows unauthorized creation of administrator accounts without authentication. This vulnerability ena…
rss:The Hacker News
19:18 KSA
CRITICAL malware
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices Dutch authorities successfully dismantled a large-scale botnet that compromised approximately 17 million devices including computers, tablets, smartphones, and IoT devices. The botnet was b…
📰 Cybersecurity News
0 articles
📰 No news aggregated today yet

This digest is updated automatically every day — Last updated: Sunday, May 31, 2026
CVE Archive · Threats · News

📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.