|
931
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does …
|
-
|
CVE-2026-9094
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.War…
|
-
|
CVE-2026-9096
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and pa…
|
-
|
CVE-2026-9097
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
- |
|
-
|
-
|
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnReques…
|
-
|
CVE-2026-9098
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
- |
|
-
|
-
|
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe wi…
|
CWE-22 CWE-269 CWE-284 CWE-732
Path Traversal Improper Privilege Management Improper Access Control Incorrect Permission Assignment for Critical Resource
|
CVE-2026-9789
|
2026-05-29 02:58 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNo…
|
CWE-20 CWE-617 CWE-755
Improper Input Validation Reachable Assertion Improper Handling of Exceptional Conditions
|
CVE-2026-44319
|
2026-05-29 02:50 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a n…
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44322
|
2026-05-29 02:37 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
4.3 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-1248
|
2026-05-29 02:19 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
6.6 |
MEDIUM
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-48918
|
2026-05-29 02:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-9818
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|