64 CVEs published May 24, 2026: 0 critical, 26 high, 16 medium, 22 low; 0 in KEV; 1 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 39 in the results table.
Yesterday's Results
64 CVEs published. 25 box scores, 39 table rows — nothing truncated.
Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0209 80.0 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 8.9 .0173 75.7 —
AFFECTED
Product Versions Fixed
A8000RU 7.1cu.643_b20200521 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
NousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0166 74.6 —
AFFECTED
Product Versions Fixed
hermes-agent 5157f5427f19488b31c6fdebbacd15d798ce7f63 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax EW-7438RPn webs formWizSurvey os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0152 72.4 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.0 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax EW-7438RPn POST Request formHwSet command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0140 70.1 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.28a – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax BR-6675nD POST Request formHwSet command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0117 64.8 —
AFFECTED
Product Versions Fixed
BR-6675nD 1.12 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax EW-7438RPn POST Request formAccep formAccept command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.4 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.12 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax EW-7438RPn Setting formConnectionSetting command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.4 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.12 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwlanSetup command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.4 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.12 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax BR-6675nD POST Request formWpsStart command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.4 —
AFFECTED
Product Versions Fixed
BR-6675nD 1.12 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax BR-6675nD POST Request formUSBStorage command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.4 —
AFFECTED
Product Versions Fixed
BR-6675nD 1.12 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax BR-6675nD POST Request formWlanMP command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.4 —
AFFECTED
Product Versions Fixed
BR-6675nD 1.12 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
NousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N N L L 5.5 .0068 49.2 —
AFFECTED
Product Versions Fixed
hermes-agent 2026.4.0 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax EW-7438RPn webs formWizSurvey buffer overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0054 43.0 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.0 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
Edimax BR-6675nD POST Request formPPTPSetup buffer overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0054 43.0 —
AFFECTED
Product Versions Fixed
BR-6675nD 1.12 – —
TIMELINE
May 23 Reserved by CNA
May 24 Published (CNA: VulDB)
huggingface huggingface/transformers — Arbitrary Remote Code Execution via `_attn_implementation_internal` Config Injection in huggingface/transformers
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L N R U H H H 7.8 .0048 39.3 —
AFFECTED
Product Versions Fixed
huggingface/transformers unspecified – —
TIMELINE
Mar 18 Reserved by CNA
May 24 Public exploit reference published
May 24 Published (CNA: @huntr_ai)
GNU GNU SASL — In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via…
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0046 37.7 —
AFFECTED
Product Versions Fixed
GNU SASL unspecified —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: mitre)
Besen BS20 EV Charging Station OTA Update Installation improper authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N H H H 8.2 .0045 37.7 —
AFFECTED
Product Versions Fixed
BS20 EV Charging Station 20260426 – —
TIMELINE
May 24 Reserved by CNA
May 24 Published (CNA: VulDB)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-9344 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn webs formWpsStart stack-based overflow |
| CVE-2026-9346 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn webs formWirelessTbl buffer overflow |
| CVE-2026-9348 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn webs mp stack-based overflow |
| CVE-2026-9360 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn POST Request formwlencrypt24g buffer overflow |
| CVE-2026-9380 | 7.4 | 37.0 | Edimax | BR-6675nD | CWE-119 | Edimax BR-6675nD POST Request formL2TPSetup buffer overflow |
| CVE-2026-9381 | 7.4 | 37.0 | Edimax | BR-6675nD | CWE-119 | Edimax BR-6675nD POST Request formPPPoESetup buffer overflow |
| CVE-2026-9393 | 7.4 | 37.0 | H3C | Magic B0 | CWE-119 | H3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow |
| CVE-2026-9399 | 7.4 | 37.0 | Edimax | BR-6675nD | CWE-119 | Edimax BR-6675nD POST Request formsetPPPoE buffer overflow |
| CVE-2026-9401 | 7.4 | 37.0 | Edimax | BR-6675nD | CWE-119 | Edimax BR-6675nD POST Request formWanTcpipSetup buffer overflow |
| CVE-2026-9403 | 7.4 | 37.0 | Edimax | BR-6675nD | CWE-119 | Edimax BR-6675nD POST Request formWlSiteSurvey buffer overflow |
| CVE-2026-9389 | 7.4 | 36.5 | Tenda | F456 | CWE-119 | Tenda F456 L7Im frmL7ImForm buffer overflow |
| CVE-2026-9371 | 2.9 | 36.4 | ItzCrazyKns | Vane | CWE-287 | ItzCrazyKns Vane API route.ts missing authentication |
| CVE-2026-9349 | 5.5 | 34.1 | calcom | cal.diy | CWE-200 | calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx … |
| CVE-2026-9368 | 5.5 | 31.2 | NousResearch | hermes-agent | CWE-264 | NousResearch hermes-agent Environment Variable code_execution_tool.py execute… |
| CVE-2026-9373 | 6.3 | 28.8 | n/a | JeecgBoot | CWE-287 | JeecgBoot OpenAPI Endpoint call improper authentication |
| CVE-2026-9354 | 5.5 | 26.6 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent Slack Agent/Mattermost Agent escape output |
| CVE-2026-9358 | 2.1 | 25.4 | n/a | postcss-selector-parser | CWE-404 | postcss-selector-parser AST Serialization container.js toString recursion |
| CVE-2026-9365 | 2.9 | 24.7 | n/a | Ettercap | CWE-119 | Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow |
| CVE-2026-9353 | 5.5 | 23.1 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py inje… |
| CVE-2026-9366 | 5.5 | 23.1 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent prompt_builder.py _scan_context_content injection |
| CVE-2026-3515 | 8.5 | 22.3 | prefecthq | prefecthq/prefect | CWE-88 | Argument Injection in prefecthq/prefect |
| CVE-2026-9398 | 1.3 | 21.9 | Besen | BS20 EV Charging Station | CWE-287 | Besen BS20 EV Charging Station BLE/WiFi authentication replay |
| CVE-2026-9352 | 5.5 | 21.1 | NousResearch | hermes-agent | CWE-200 | NousResearch hermes-agent Messaging Gateway local.py _make_run_env informatio… |
| CVE-2026-9357 | 2.0 | 20.4 | n/a | vBulletin | CWE-79 | vBulletin Login cross site scripting |
| CVE-2026-9350 | 5.5 | 20.3 | NousResearch | hermes-agent | CWE-862 | NousResearch hermes-agent Batch Runner approval.py check_all_command_guards a… |
| CVE-2026-9372 | 5.5 | 20.3 | ItzCrazyKns | Vane | CWE-918 | ItzCrazyKns Vane Model Provider API route.ts server-side request forgery |
| CVE-2026-9396 | 2.9 | 19.0 | Besen | BS20 EV Charging Station | CWE-1021 | Besen BS20 EV Charging Station Firmware Version Check ui layer |
| CVE-2026-9355 | 5.5 | 17.1 | SourceCodester | Hospitals Patient Records Management System | CWE-74 | SourceCodester Hospitals Patient Records Management System Master.php save_pa… |
| CVE-2026-9356 | 5.5 | 17.1 | SourceCodester | Hospitals Patient Records Management System | CWE-74 | SourceCodester Hospitals Patient Records Management System manage_history.php… |
| CVE-2026-9364 | 5.5 | 17.1 | projectworlds | Online Art Gallery Shop | CWE-74 | projectworlds Online Art Gallery Shop adminHome.php sql injection |
| CVE-2026-9383 | 5.5 | 17.1 | itsourcecode | Electronic Judging System | CWE-74 | itsourcecode Electronic Judging System login.php sql injection |
| CVE-2026-9376 | 2.1 | 16.9 | n/a | JPress | CWE-266 | JPress UCenter Article Submission Endpoint doWriteSave improper authorization |
| CVE-2026-9369 | 1.9 | 13.9 | NousResearch | hermes-agent | CWE-697 | NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard… |
| CVE-2026-9370 | 2.9 | 10.4 | ulisesbocchio | jasypt-spring-boot | CWE-759 | ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecret… |
| CVE-2026-9377 | 1.9 | 10.4 | SourceCodester | SUP Online Shopping | CWE-79 | SourceCodester SUP Online Shopping productedit.php cross site scripting |
| CVE-2026-9374 | 5.3 | 9.5 | yangzongzhuan | RuoYi-Vue | CWE-284 | yangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUploadUtils.upload … |
| CVE-2026-9394 | 1.3 | 9.2 | Besen | BS20 EV Charging Station | CWE-521 | Besen BS20 EV Charging Station Bluetooth Low Energy weak password |
| CVE-2026-48832 | 3.5 | 8.4 | SPIP | SPIP | CWE-601 | action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirec… |
| CVE-2026-9395 | 2.0 | 5.5 | Besen | BS20 EV Charging Station | CWE-522 | Besen BS20 EV Charging Station BLE/UDP insufficiently protected credentials |