Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29232
Total
2268
Critical
8711
High
9096
Medium
CVE ID Severity Score Description Published
CVE-2026-6839 MEDIUM 6.6 Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source … Apr 22, 2026
CVE-2026-41667 MEDIUM 6.6 Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is … Apr 22, 2026
CVE-2026-41666 MEDIUM 6.6 Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version … Apr 22, 2026
CVE-2026-41665 MEDIUM 6.1 Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior … Apr 22, 2026
CVE-2026-41664 MEDIUM 6.6 Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is … Apr 22, 2026
CVE-2026-40450 MEDIUM 6.6 Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected … Apr 22, 2026
CVE-2026-40449 MEDIUM 6.6 Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version … Apr 22, 2026
CVE-2026-40448 MEDIUM 5.3 Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is … Apr 22, 2026
CVE-2026-22754 HIGH 7.5 Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet … Apr 22, 2026
CVE-2026-22753 HIGH 7.5 Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter … Apr 22, 2026
CVE-2026-22748 MEDIUM 5.3 Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling … Apr 22, 2026
CVE-2026-22747 MEDIUM 6.8 Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for … Apr 22, 2026
CVE-2026-22746 LOW 3.7 Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's … Apr 22, 2026
CVE-2026-40451 MEDIUM 6.1 DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's … Apr 22, 2026
CVE-2026-6835 MEDIUM 6.1 The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, … Apr 22, 2026
CVE-2026-6834 MEDIUM 6.5 The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method. Apr 22, 2026
CVE-2026-6833 MEDIUM 6.5 The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. Apr 22, 2026
CVE-2026-6416 LOW 2.7 Tanium addressed an uncontrolled resource consumption vulnerability in Interact. Apr 22, 2026
CVE-2026-6408 LOW 2.7 Tanium addressed an information disclosure vulnerability in Tanium Server. Apr 22, 2026
CVE-2026-6392 LOW 2.7 Tanium addressed an information disclosure vulnerability in Threat Response. Apr 22, 2026
CVE-2026-6386 MEDIUM 6.2 In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled … Apr 22, 2026
CVE-2026-5398 HIGH 8.4 The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process … Apr 22, 2026
CVE-2026-41458 UNKNOWN OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by … Apr 22, 2026
CVE-2026-41457 UNKNOWN OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions … Apr 22, 2026
CVE-2026-41146 UNKNOWN facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value … Apr 22, 2026