|
1271
|
3.7 |
LOW
Adjacent
|
-
|
-
|
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could se…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2026-44474
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1272
|
7.1 |
HIGH
Adjacent
|
-
|
-
|
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does…
|
CWE-358 CWE-863
Improperly Implemented Security Check for Standard Incorrect Authorization
|
CVE-2026-44473
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1273
|
- |
|
-
|
-
|
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verific…
|
CWE-295 CWE-297
Improper Certificate Validation Improper Validation of Certificate with Host Mismatch
|
CVE-2026-42790
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1274
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.
|
-
|
CVE-2026-38931
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1275
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via …
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-12686
|
2026-05-28 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1276
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Account Manager for WooCom…
|
CWE-862
Missing Authorization
|
CVE-2022-41656
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1277
|
7.5 |
HIGH
Network
|
ibm
|
http_server
|
IBM HTTP Server 8.5, and 9.0
|
CWE-94
Code Injection
|
CVE-2026-9170
|
2026-05-28 02:07 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1278
|
9.8 |
CRITICAL
Network
|
microsoft
|
power_pages
|
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
|
CWE-77
Command Injection
|
CVE-2026-23652
|
2026-05-28 02:01 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1279
|
9.8 |
CRITICAL
Network
|
microsoft
|
entra_id
|
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-33843
|
2026-05-28 01:50 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1280
|
8.8 |
HIGH
Network
|
microsoft
|
azure_privileged_identity_management
|
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-35430
|
2026-05-28 01:48 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|