|
31
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6538
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-1325
Improperly Controlled Sequential Memory Allocation
|
CVE-2026-6867
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-1325
Improperly Controlled Sequential Memory Allocation
|
CVE-2026-6869
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2026-6870
|
2026-05-2 03:11 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
7.5 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-prod…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42402
|
2026-05-2 03:08 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
7.5 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Po…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42403
|
2026-05-2 03:08 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
7.2 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a poli…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42404
|
2026-05-2 03:06 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
9.8 |
CRITICAL
Network
|
apache
|
mina
|
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inc…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42778
|
2026-05-2 02:55 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
9.8 |
CRITICAL
Network
|
apache
|
mina
|
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, on…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42779
|
2026-05-2 02:55 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
5.9 |
MEDIUM
Network
|
apache
|
airflow
|
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between …
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-41016
|
2026-05-2 02:54 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|