|
151
|
7.5 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Po…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42403
|
2026-05-2 03:08 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
7.2 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a poli…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42404
|
2026-05-2 03:06 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
9.8 |
CRITICAL
Network
|
apache
|
mina
|
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inc…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42778
|
2026-05-2 02:55 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
9.8 |
CRITICAL
Network
|
apache
|
mina
|
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, on…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42779
|
2026-05-2 02:55 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
5.9 |
MEDIUM
Network
|
apache
|
airflow
|
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between …
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-41016
|
2026-05-2 02:54 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
9.6 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-7321
|
2026-05-2 02:54 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
5.3 |
MEDIUM
Network
|
ibm
|
db2
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2025-14688
|
2026-05-2 02:52 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
6.5 |
MEDIUM
Network
|
ibm
|
db2
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially cra…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-36122
|
2026-05-2 02:52 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
6.5 |
MEDIUM
Network
|
ibm
|
db2
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-1577
|
2026-05-2 02:52 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
9.8 |
CRITICAL
Network
|
exim
|
exim
|
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…
New
|
CWE-684 CWE-787
Incorrect Provision of Specified Functionality Out-of-bounds Write
|
CVE-2026-40685
|
2026-05-2 02:51 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|