Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25513
Total
1895
Critical
7789
High
8000
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40989 | MEDIUM | 5.7 | Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 … | Jun 01, 2026 |
| CVE-2026-37235 | UNKNOWN | — | FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function valid_xapp_id() only checks that … | Jun 01, 2026 |
| CVE-2026-37233 | HIGH | 7.5 | FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_id against itself (m0->xapp_id) instead of … | Jun 01, 2026 |
| CVE-2026-37232 | HIGH | 8.6 | An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in openair2/E2AP/RAN_FUNCTION/O-RAN/ran_func_kpm_subs.c (lines … | Jun 01, 2026 |
| CVE-2026-37231 | HIGH | 7.5 | FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ E42_SETUP_REQUESTs, the 16-bit counter wraps around … | Jun 01, 2026 |
| CVE-2026-37230 | HIGH | 7.5 | FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, … | Jun 01, 2026 |
| CVE-2026-37229 | HIGH | 7.5 | FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., … | Jun 01, 2026 |
| CVE-2026-37228 | HIGH | 7.5 | FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() … | Jun 01, 2026 |
| CVE-2026-37226 | HIGH | 7.5 | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in … | Jun 01, 2026 |
| CVE-2026-30963 | LOW | 3.9 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to … | Jun 01, 2026 |
| CVE-2026-23638 | MEDIUM | 6.5 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an … | Jun 01, 2026 |
| CVE-2026-22872 | UNKNOWN | — | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the … | Jun 01, 2026 |
| CVE-2026-10283 | MEDIUM | 6.3 | A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in … | Jun 01, 2026 |
| CVE-2026-10282 | MEDIUM | 4.3 | A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to … | Jun 01, 2026 |
| CVE-2026-10281 | HIGH | 7.3 | A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. … | Jun 01, 2026 |
| CVE-2026-10280 | HIGH | 7.3 | A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP … | Jun 01, 2026 |
| CVE-2026-10279 | MEDIUM | 6.3 | A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation … | Jun 01, 2026 |
| CVE-2026-10278 | MEDIUM | 6.3 | A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a … | Jun 01, 2026 |
| CVE-2026-10277 | MEDIUM | 6.3 | A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail … | Jun 01, 2026 |
| CVE-2026-10276 | MEDIUM | 6.3 | A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation … | Jun 01, 2026 |
| CVE-2026-0072 | UNKNOWN | — | In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User … | Jun 01, 2026 |
| CVE-2024-52011 | UNKNOWN | — | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` … | Jun 01, 2026 |
| CVE-2026-8643 | UNKNOWN | — | pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry … | Jun 01, 2026 |
| CVE-2026-8501 | HIGH | 7.8 | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and … | Jun 01, 2026 |
| CVE-2026-46243 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, … | Jun 01, 2026 |