Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-38808 | MEDIUM | 5.3 | SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components | May 27, 2026 |
| CVE-2026-38807 | HIGH | 8.8 | Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component | May 27, 2026 |
| CVE-2025-69600 | HIGH | 7.8 | Command injection in Raynet rvia 12.6.4392.49-amd64.deb allows adversaries to execute commands via getconfig, and upload through the URL argument, and oracle through the -o flag … | May 27, 2026 |
| CVE-2025-67903 | UNKNOWN | — | Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. | May 27, 2026 |
| CVE-2026-49054 | MEDIUM | 4.3 | Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a … | May 27, 2026 |
| CVE-2026-48027 | CRITICAL | 9.8 | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 … | May 27, 2026 |
| CVE-2026-45335 | MEDIUM | 5.4 | WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, … | May 27, 2026 |
| CVE-2026-45027 | MEDIUM | 5.9 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's … | May 27, 2026 |
| CVE-2026-44483 | HIGH | 8.2 | RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used … | May 27, 2026 |
| CVE-2026-44475 | MEDIUM | 6.1 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP … | May 27, 2026 |
| CVE-2026-44474 | LOW | 3.7 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures … | May 27, 2026 |
| CVE-2026-44473 | HIGH | 7.1 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse … | May 27, 2026 |
| CVE-2026-44353 | MEDIUM | 6.5 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do … | May 27, 2026 |
| CVE-2026-44330 | CRITICAL | 10.0 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A … | May 27, 2026 |
| CVE-2026-44329 | CRITICAL | 10.0 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. … | May 27, 2026 |
| CVE-2026-44328 | HIGH | 8.2 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. … | May 27, 2026 |
| CVE-2026-44327 | CRITICAL | 10.0 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A … | May 27, 2026 |
| CVE-2026-44326 | CRITICAL | 9.4 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network … | May 27, 2026 |
| CVE-2026-44325 | HIGH | 7.5 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug … | May 27, 2026 |
| CVE-2026-44324 | MEDIUM | 6.5 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler panics on a single authenticated request … | May 27, 2026 |
| CVE-2026-44323 | MEDIUM | 4.3 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler contains a nil-pointer dereference reachable from … | May 27, 2026 |
| CVE-2026-44322 | HIGH | 7.5 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a nil-pointer dereference when the … | May 27, 2026 |
| CVE-2026-44321 | HIGH | 7.5 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. … | May 27, 2026 |
| CVE-2026-44320 | HIGH | 7.3 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A … | May 27, 2026 |
| CVE-2026-44319 | HIGH | 7.5 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot … | May 27, 2026 |