Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29082
Total
2258
Critical
8681
High
9062
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-6839 | MEDIUM | 6.6 | Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source … | Apr 22, 2026 |
| CVE-2026-41667 | MEDIUM | 6.6 | Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is … | Apr 22, 2026 |
| CVE-2026-41666 | MEDIUM | 6.6 | Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version … | Apr 22, 2026 |
| CVE-2026-41665 | MEDIUM | 6.1 | Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior … | Apr 22, 2026 |
| CVE-2026-41664 | MEDIUM | 6.6 | Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is … | Apr 22, 2026 |
| CVE-2026-40450 | MEDIUM | 6.6 | Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected … | Apr 22, 2026 |
| CVE-2026-40449 | MEDIUM | 6.6 | Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version … | Apr 22, 2026 |
| CVE-2026-40448 | MEDIUM | 5.3 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is … | Apr 22, 2026 |
| CVE-2026-22754 | HIGH | 7.5 | Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet … | Apr 22, 2026 |
| CVE-2026-22753 | HIGH | 7.5 | Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter … | Apr 22, 2026 |
| CVE-2026-22748 | MEDIUM | 5.3 | Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling … | Apr 22, 2026 |
| CVE-2026-22747 | MEDIUM | 6.8 | Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for … | Apr 22, 2026 |
| CVE-2026-22746 | LOW | 3.7 | Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's … | Apr 22, 2026 |
| CVE-2026-40451 | MEDIUM | 6.1 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's … | Apr 22, 2026 |
| CVE-2026-6835 | MEDIUM | 6.1 | The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, … | Apr 22, 2026 |
| CVE-2026-6834 | MEDIUM | 6.5 | The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method. | Apr 22, 2026 |
| CVE-2026-6833 | MEDIUM | 6.5 | The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | Apr 22, 2026 |
| CVE-2026-6416 | LOW | 2.7 | Tanium addressed an uncontrolled resource consumption vulnerability in Interact. | Apr 22, 2026 |
| CVE-2026-6408 | LOW | 2.7 | Tanium addressed an information disclosure vulnerability in Tanium Server. | Apr 22, 2026 |
| CVE-2026-6392 | LOW | 2.7 | Tanium addressed an information disclosure vulnerability in Threat Response. | Apr 22, 2026 |
| CVE-2026-6386 | MEDIUM | 6.2 | In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled … | Apr 22, 2026 |
| CVE-2026-5398 | HIGH | 8.4 | The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process … | Apr 22, 2026 |
| CVE-2026-41458 | UNKNOWN | — | OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by … | Apr 22, 2026 |
| CVE-2026-41457 | UNKNOWN | — | OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions … | Apr 22, 2026 |
| CVE-2026-41146 | UNKNOWN | — | facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value … | Apr 22, 2026 |