| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-10567 | 1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting | 1Panel-dev | CordysCRM | Low | 3.5 | 2026-06-02 02:00:15 | Deep Dive |
| CVE-2026-10510 | GeniexWebView XSS in com.transsion.aiassistantlifestyle | TECNO Mobile | com.transsion.aiassistantlifestyle | - | - | 2026-06-02 01:56:42 | Deep Dive |
| CVE-2026-3870 | Zyxel VMG4005-B50B固件UpnP缓冲区溢出致DoS | Zyxel | VMG4005-B50B firmware | Medium | 6.5 | 2026-06-02 01:54:49 | Deep Dive |
| CVE-2026-10566 | FoundationAgents MetaGPT schema.py Message.check_instruct_content deserialization | FoundationAgents | MetaGPT | Medium | 5.3 | 2026-06-02 01:45:10 | Deep Dive |
| CVE-2026-10565 | Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition | - | Open5GS | Low | 3.1 | 2026-06-02 01:30:10 | Deep Dive |
| CVE-2026-10100 | Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting | pattihis | Simple Custom Login Page | Medium | 4.4 | 2026-06-02 01:28:05 | Deep Dive |
| CVE-2026-3722 | Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) <= 4.9 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attribute | arunbasillal | Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) | Medium | 6.4 | 2026-06-02 01:28:03 | Deep Dive |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | SourceCodester | Pizzafy Ecommerce System | Medium | 6.3 | 2026-06-02 01:15:10 | Deep Dive |
| CVE-2026-10558 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | SourceCodester | Pizzafy Ecommerce System | Medium | 6.3 | 2026-06-02 01:00:15 | Deep Dive |
| CVE-2026-10550 | elunez eladmin Application Deployment App.java command injection | elunez | eladmin | Medium | 6.3 | 2026-06-02 00:45:10 | Deep Dive |
| CVE-2026-10548 | NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication | NousResearch | hermes-agent | Medium | 5.3 | 2026-06-02 00:30:10 | Deep Dive |
| CVE-2026-10529 | westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting | westboy | CicadasCMS | Low | 2.4 | 2026-06-02 00:15:15 | Deep Dive |
| CVE-2026-10528 | Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow | Orthanc | DICOM Server | Low | 3.3 | 2026-06-02 00:00:17 | Deep Dive |
| CVE-2026-35717 | VIVOTEK FD8136栈溢出漏洞 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |
| CVE-2026-35716 | VIVOTEK FD8136栈缓冲区溢出漏洞 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |
| CVE-2026-35718 | VIVOTEK FD8136-VVTK 0300a路径遍历漏洞 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |
| CVE-2026-38978 | Transmission 4.1.1 WebUI/RPC 点击劫持漏洞 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |
| CVE-2026-30652 | Vivotek FD8136固件远程缓冲区溢出漏洞 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |
| CVE-2026-30649 | VIVOTEK FD8136-VVTK-0300a CGI缓冲区溢出导致任意代码执行 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |
| CVE-2026-30650 | Vivotek FD8136 VVTK-0300a远程代码执行漏洞 | - | - | - | - | 2026-06-02 00:00:00 | Deep Dive |