May 2026 (30)
CVE-2018-25372 - MedDream PACS Server Premium Unauthenticated SQL Injection
2 rules 1 TTP 1 CVEMedDream PACS Server Premium 6.7.1.1 is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the email parameter via a crafted POST request to the userSignup.php endpoint.
MooSocial Store Plugin 2.6 Blind SQL Injection Vulnerability (CVE-2018-25371)
2 rules 1 TTP 1 CVEMooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability, identified as CVE-2018-25371, allowing unauthenticated attackers to manipulate database queries via the 'product' parameter, potentially leading to sensitive data extraction.
NordVPN Denial-of-Service Vulnerability (CVE-2018-25368)
2 rules 1 TTP 1 CVENordVPN version 6.14.31 is vulnerable to a denial-of-service attack (CVE-2018-25368) where an unauthenticated attacker can crash the application by submitting an excessively long string in the password field.
CuteFTP 5.0 XP Local Buffer Overflow Vulnerability (CVE-2018-25366)
2 rules 2 TTPs 1 CVECuteFTP 5.0 XP is vulnerable to a buffer overflow (CVE-2018-25366), allowing local attackers to execute arbitrary code by injecting a malicious payload into the Site Manager label field.
Twitter-Clone 1 SQL Injection Vulnerability (CVE-2018-25364)
2 rules 1 TTP 1 CVETwitter-Clone 1 is vulnerable to SQL injection via the name parameter in the search.php endpoint, allowing unauthenticated attackers to execute arbitrary SQL queries and extract sensitive information (CVE-2018-25364).
Twitter-Clone 1 SQL Injection Vulnerability (CVE-2018-25362)
2 rules 1 TTP 1 CVETwitter-Clone 1 is vulnerable to SQL injection via the userid parameter in follow.php, allowing attackers to manipulate database queries and extract sensitive information such as usernames, passwords, and database credentials.
AgataSoft Auto PingMaster 1.5 Stack-Based Buffer Overflow (CVE-2018-25360)
2 rules 3 TTPs 1 CVEAgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability (CVE-2018-25360) in the Trace Route host name field, allowing local attackers to execute arbitrary code by triggering structured exception handling.
Splinterware System Scheduler Pro 5.12 Privilege Escalation via Insecure Permissions (CVE-2018-25359)
2 rules 1 TTP 1 CVESplinterware System Scheduler Pro 5.12 is vulnerable to privilege escalation (CVE-2018-25359) due to insecure file permissions, allowing low-privilege users to replace the service executable with a malicious one, leading to arbitrary code execution as LocalSystem.
Edimax EW-7438RPn Stack-Based Buffer Overflow Vulnerability (CVE-2026-9459)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-9459) exists in the formConnectionSetting function of /goform/formConnectionSetting in Edimax EW-7438RPn 1.31, allowing a remote attacker to execute arbitrary code by manipulating the max_Conn/timeOut arguments, with a public exploit available.
FoundDream miniclawd Command Injection Vulnerability (CVE-2026-9453)
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-9453) exists in FoundDream miniclawd, where manipulation of the requires.bins argument in /src/application/skills-loader.ts allows remote command execution, and the exploit is publicly available.
CVE-2026-9452 FoundDream miniclawd Remote Command Injection
2 rules 1 TTP 1 CVEA command injection vulnerability exists in FoundDream miniclawd within the ExecTool.execute function in /src/tools/exec.ts, which can be triggered remotely, allowing attackers to execute arbitrary OS commands.
SourceCodester Simple POS and Inventory System SQL Injection Vulnerability (CVE-2026-9447)
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-9447) exists in SourceCodester Simple POS and Inventory System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'Name' argument in the /user/search.php file.
Tenda F1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-9431)
2 rules 1 TTP 1 CVEA remote stack-based buffer overflow vulnerability (CVE-2026-9431) exists in the fromPptpUserAdd function of the /goform/PptpUserAdd file in Tenda F1202 firmware version 1.2.0.20(408), allowing unauthenticated attackers to potentially execute arbitrary code.
Tenda F1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-9430)
2 rules 2 TTPs 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-9430) exists in Tenda F1202 version 1.2.0.20(408) due to manipulation of the 'dips' argument in the 'formGstDhcpSetSer' function of '/goform/GstDhcpSetSerof', allowing remote code execution.
Tenda F1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-9429)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-9429) exists in Tenda F1202 version 1.2.0.20(408) within the formWrlExtraSet function of the /goform/WrlExtraSet file, allowing a remote attacker to execute arbitrary code by manipulating the delno argument; a public exploit is available.
CVE-2026-9426 - Edimax EW-7438RPn Stack-Based Buffer Overflow
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability exists in Edimax EW-7438RPn version 1.31 in the formHwSet function of the /goform/formHwSet file, which can be triggered by manipulating the Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url argument, potentially leading to remote code execution.
Totolink A8000RU Command Injection Vulnerability (CVE-2026-9475)
2 rules 1 TTP 1 CVETotolink A8000RU version 7.1cu.643_b20200521 is vulnerable to remote OS command injection via manipulation of the Comment argument in the setIpQosRules function, allowing unauthenticated attackers to execute arbitrary commands on the device.
CVE-2026-9456 - Totolink A8000RU Remote Command Injection
2 rules 1 TTP 1 CVETotolink A8000RU version 7.1cu.643_b20200521 is vulnerable to remote command injection via the setOpenVpnCfg function, allowing unauthenticated attackers to execute arbitrary commands on the device.
Totolink A8000RU Command Injection Vulnerability (CVE-2026-9408)
3 rules 1 TTP 1 CVETotolink A8000RU version 7.1cu.643_b20200521 is vulnerable to command injection via the setStaticDhcpRules function in the /cgi-bin/cstecgi.cgi file, allowing remote attackers to execute arbitrary OS commands by manipulating the 'enable' argument, and a public exploit is available.
Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php
2 rules 2 TTPs 1 CVEDolibarr ERP CRM 7.0.3 is vulnerable to remote code evaluation, allowing unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter, leading to arbitrary command execution.
userSpice Username Enumeration Vulnerability (CVE-2018-25350)
2 rules 1 TTP 1 CVEuserSpice 4.3.24 contains a username enumeration vulnerability, allowing unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint and analyzing the response for the 'taken' string.
CVE-2026-47280 - Azure Resource Manager (ARM) Improper Authentication Vulnerability
2 rules 1 TTPCVE-2026-47280 is an improper authentication vulnerability in Azure Resource Manager (ARM) that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42901 - Microsoft Entra ID Origin Validation Error Leads to Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-42901 is an origin validation error in Microsoft Entra ID that allows an unauthorized attacker to elevate privileges over a network, potentially granting them unauthorized access and control.
CVE-2026-41104 - Microsoft Planetary Computer Pro Deserialization Vulnerability
2 rules 1 TTP 1 CVECVE-2026-41104 is a critical vulnerability in Microsoft Planetary Computer Pro that allows an unauthorized attacker to disclose information over a network by deserializing untrusted data.
CVE-2026-41090: Microsoft Copilot Command Injection Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-41090 is a command injection vulnerability in Microsoft Copilot, allowing an unauthorized attacker to perform tampering over a network.
CVE-2026-40412: Unrestricted File Upload in Azure Orbital Spatio Leads to Remote Code Execution
2 rules 1 TTP 1 CVECVE-2026-40412 is a critical vulnerability in Azure Orbital Spatio that allows an unauthenticated attacker to execute arbitrary code over a network by uploading a file with a dangerous type.
CVE-2026-40411: Azure Virtual Network Gateway Improper Input Validation RCE
2 rules 1 TTP 1 CVECVE-2026-40411 describes an improper input validation vulnerability in Azure Virtual Network Gateway that allows an authorized attacker to execute code over a network.
CVE-2026-33843 Authentication Bypass in Microsoft Azure Active Directory B2C
2 rules 1 TTP 1 CVECVE-2026-33843 allows an unauthorized attacker to elevate privileges over a network in Microsoft Azure Active Directory B2C due to an authentication bypass using an alternate path or channel.
CVE-2026-23652 - Microsoft Power Pages Command Injection
2 rules 1 TTP 1 CVECVE-2026-23652 is a critical command injection vulnerability in Microsoft Power Pages, allowing an unauthorized attacker to execute arbitrary code over the network by injecting commands.
CVE-2026-44930: Apache CXF LDAP Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-44930 is an LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF that may allow an attacker to retrieve arbitrary certificates from the repository.