| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-6708 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter | higheredlab | HEL Online Classroom: AI-powered Online Classrooms | Medium | 5.3 | 2026-05-12 07:48:16 | Deep Dive |
| CVE-2026-6402 | webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins | webpack-dev-server | webpack-dev-server | Medium | 5.3 | 2026-05-12 07:45:21 | Deep Dive |
| CVE-2026-35227 | Improper resource management in CODESYS Modbus TCP Server | CODESYS | CODESYS Modbus | 中危 | - | 2026-05-12 07:14:42 | Deep Dive |
| CVE-2026-1185 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 5.4 | 2026-05-12 05:49:47 | Deep Dive |
| CVE-2026-0804 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 6.7 | 2026-05-12 05:46:45 | Deep Dive |
| CVE-2026-0802 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 6.0 | 2026-05-12 05:44:59 | Deep Dive |
| CVE-2026-0541 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 6.7 | 2026-05-12 05:42:28 | Deep Dive |
| CVE-2026-1681 | net: Stack Overflow with Ping (to own IP Address) via Shell | zephyrproject-rtos | Zephyr | Medium | 6.1 | 2026-05-12 05:39:03 | Deep Dive |
| CVE-2026-41872 | Kura Sushi Official App 信任管理问题漏洞 | EPG, Inc. | "Kura Sushi Official App" for Android | - | - | 2026-05-12 05:21:43 | Deep Dive |
| CVE-2026-41530 | Chitora Lhaz 路径遍历漏洞 | Chitora soft | Lhaz | - | - | 2026-05-12 05:21:11 | Deep Dive |
| CVE-2026-45430 | Backdrop CMS Salesforce 跨站请求伪造漏洞 | Backdrop CMS contributed projects | backdrop-contrib/salesforce | High | 7.1 | 2026-05-12 04:06:24 | Deep Dive |
| CVE-2026-7287 | Zyxel NWA1100-N 安全漏洞 | Zyxel | NWA1100-N firmware | High | 7.5 | 2026-05-12 03:56:13 | Deep Dive |
| CVE-2026-7257 | Zyxel WRE6505 安全漏洞 | Zyxel | WRE6505 v2 firmware | Medium | 4.4 | 2026-05-12 03:31:03 | Deep Dive |
| CVE-2026-7256 | Zyxel WRE6505 操作系统命令注入漏洞 | Zyxel | WRE6505 v2 firmware | High | 8.8 | 2026-05-12 03:25:33 | Deep Dive |
| CVE-2026-7255 | Zyxel WRE6505 安全漏洞 | Zyxel | WRE6505 v2 firmware | Medium | 6.5 | 2026-05-12 03:22:19 | Deep Dive |
| CVE-2026-40137 | Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUNCHER) | SAP_SE | Business Server Pages Application (TAF_APPLAUNCHER) | Medium | 6.1 | 2026-05-12 02:23:18 | Deep Dive |
| CVE-2026-40136 | Denial of service (DoS) in SAP Financial Consolidation | SAP_SE | SAP Financial Consolidation | Medium | 4.3 | 2026-05-12 02:21:51 | Deep Dive |
| CVE-2026-40135 | OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform | SAP_SE | SAP NetWeaver Application Server for ABAP and ABAP Platform | Medium | 6.5 | 2026-05-12 02:21:41 | Deep Dive |
| CVE-2026-40134 | Missing Authorization Check in SAP Incentive and Commission Management | SAP_SE | SAP Incentive and Commission Management | Medium | 4.3 | 2026-05-12 02:21:28 | Deep Dive |
| CVE-2026-40133 | Missing Authorization check in SAP S/4HANA Condition Maintenance | SAP_SE | SAP S/4HANA Condition Maintenance | Medium | 6.3 | 2026-05-12 02:21:18 | Deep Dive |