Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25513
Total
1895
Critical
7789
High
8000
Medium
CVE ID Severity Score Description Published
CVE-2026-40989 MEDIUM 5.7 Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 … Jun 01, 2026
CVE-2026-37235 UNKNOWN FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function valid_xapp_id() only checks that … Jun 01, 2026
CVE-2026-37233 HIGH 7.5 FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_id against itself (m0->xapp_id) instead of … Jun 01, 2026
CVE-2026-37232 HIGH 8.6 An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in openair2/E2AP/RAN_FUNCTION/O-RAN/ran_func_kpm_subs.c (lines … Jun 01, 2026
CVE-2026-37231 HIGH 7.5 FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ E42_SETUP_REQUESTs, the 16-bit counter wraps around … Jun 01, 2026
CVE-2026-37230 HIGH 7.5 FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, … Jun 01, 2026
CVE-2026-37229 HIGH 7.5 FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., … Jun 01, 2026
CVE-2026-37228 HIGH 7.5 FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() … Jun 01, 2026
CVE-2026-37226 HIGH 7.5 FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in … Jun 01, 2026
CVE-2026-30963 LOW 3.9 Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to … Jun 01, 2026
CVE-2026-23638 MEDIUM 6.5 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an … Jun 01, 2026
CVE-2026-22872 UNKNOWN Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the … Jun 01, 2026
CVE-2026-10283 MEDIUM 6.3 A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in … Jun 01, 2026
CVE-2026-10282 MEDIUM 4.3 A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to … Jun 01, 2026
CVE-2026-10281 HIGH 7.3 A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. … Jun 01, 2026
CVE-2026-10280 HIGH 7.3 A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP … Jun 01, 2026
CVE-2026-10279 MEDIUM 6.3 A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation … Jun 01, 2026
CVE-2026-10278 MEDIUM 6.3 A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a … Jun 01, 2026
CVE-2026-10277 MEDIUM 6.3 A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail … Jun 01, 2026
CVE-2026-10276 MEDIUM 6.3 A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation … Jun 01, 2026
CVE-2026-0072 UNKNOWN In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User … Jun 01, 2026
CVE-2024-52011 UNKNOWN launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` … Jun 01, 2026
CVE-2026-8643 UNKNOWN pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry … Jun 01, 2026
CVE-2026-8501 HIGH 7.8 Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and … Jun 01, 2026
CVE-2026-46243 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, … Jun 01, 2026