| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-10111 | sambitraj STUDENT-MANAGEMENT-SYSTEM Login Page sql injection | sambitraj | STUDENT-MANAGEMENT-SYSTEM | High | 7.3 | 2026-05-30 07:45:08 | Deep Dive |
| CVE-2026-5071 | can: Local Denial of Service via SocketCAN Send | zephyrproject-rtos | Zephyr | Medium | 6.1 | 2026-05-30 07:15:56 | Deep Dive |
| CVE-2026-10110 | code-projects Student Details Management System index.php sql injection | code-projects | Student Details Management System | High | 7.3 | 2026-05-30 06:00:14 | Deep Dive |
| CVE-2026-48840 | Exim 安全漏洞 | Exim | Exim | Medium | 5.3 | 2026-05-30 01:50:43 | Deep Dive |
| CVE-2026-9831 | ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition | Extreme Networks | Extreme Platform ONE | Medium | 6.3 | 2026-05-29 21:19:17 | Deep Dive |
| CVE-2026-46385 | iskorotkov/avro: CPU Exhaustion in Avro Decoder | iskorotkov | avro | - | - | 2026-05-29 19:59:00 | Deep Dive |
| CVE-2026-46384 | iskorotkov/avro: Integer Overflow in Avro Decoder | iskorotkov | avro | - | - | 2026-05-29 19:58:22 | Deep Dive |
| CVE-2026-45149 | brace-expansion: Large numeric range defeats documented `max` DoS protection | juliangruber | brace-expansion | Medium | 6.5 | 2026-05-29 19:55:07 | Deep Dive |
| CVE-2026-45294 | FreeScout: User Account Enumeration via Password Reset Response Differentiation | freescout-help-desk | freescout | Medium | 5.3 | 2026-05-29 19:52:23 | Deep Dive |
| CVE-2026-47123 | FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path | freescout-help-desk | freescout | High | 7.5 | 2026-05-29 19:51:41 | Deep Dive |
| CVE-2026-48557 | Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php | spatie | laravel-medialibrary | High | 8.8 | 2026-05-29 19:49:16 | Deep Dive |
| CVE-2026-48810 | FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check | freescout-help-desk | freescout | Medium | 4.3 | 2026-05-29 19:48:39 | Deep Dive |
| CVE-2026-48811 | FreeScout: Thread Deletion Bypasses Mailbox Access Revocation | freescout-help-desk | freescout | Medium | 4.3 | 2026-05-29 19:47:46 | Deep Dive |
| CVE-2026-45700 | Heap-buffer-overflow write in planar bitmap decoder | FreeRDP | FreeRDP | - | - | 2026-05-29 19:44:12 | Deep Dive |
| CVE-2026-44420 | FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS | FreeRDP | FreeRDP | High | 8.8 | 2026-05-29 19:42:23 | Deep Dive |
| CVE-2026-44422 | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion | FreeRDP | FreeRDP | High | 7.5 | 2026-05-29 19:41:47 | Deep Dive |
| CVE-2026-44421 | FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass | FreeRDP | FreeRDP | High | 8.8 | 2026-05-29 19:40:25 | Deep Dive |
| CVE-2026-46599 | Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff | golang.org/x/image | golang.org/x/image/tiff | - | - | 2026-05-29 19:35:34 | Deep Dive |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable | labring | FastGPT | Medium | 6.3 | 2026-05-29 19:33:54 | Deep Dive |
| CVE-2026-44285 | FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API | labring | FastGPT | High | 7.7 | 2026-05-29 19:32:50 | Deep Dive |