|
1241
|
- |
|
-
|
-
|
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full h…
|
CWE-20
Improper Input Validation
|
CVE-2026-45076
|
2026-05-29 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1242
|
- |
|
-
|
-
|
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing o…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45078
|
2026-05-29 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1243
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks c…
|
CWE-306 CWE-617 CWE-862
Missing Authentication for Critical Function Reachable Assertion Missing Authorization
|
CVE-2026-44321
|
2026-05-29 03:01 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1244
|
- |
|
-
|
-
|
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the defaul…
|
CWE-1391
Use of Weak Credentials
|
CVE-2026-4377
|
2026-05-29 03:00 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1245
|
- |
|
-
|
-
|
A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with applicat…
|
CWE-288 CWE-359
Authentication Bypass Using an Alternate Path or Channel Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-8990
|
2026-05-29 03:00 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1246
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without…
|
-
|
CVE-2026-9092
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1247
|
- |
|
-
|
-
|
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never…
|
-
|
CVE-2026-9093
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1248
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does …
|
-
|
CVE-2026-9094
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1249
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.War…
|
-
|
CVE-2026-9096
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1250
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and pa…
|
-
|
CVE-2026-9097
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|