|
601
|
2.7 |
LOW
Network
|
synology
|
surveillance_station
|
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to …
New
|
CWE-863
Incorrect Authorization
|
CVE-2024-47272
|
2026-05-29 03:37 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
602
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Da…
New
|
CWE-20 CWE-209
Improper Input Validation Information Exposure Through an Error Message
|
CVE-2026-42459
|
2026-05-29 03:35 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
603
|
9.4 |
CRITICAL
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44315
|
2026-05-29 03:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
604
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontrol/v1/sm-policies handler (HandleCreateSmPolicyRequest) panics with a nil-pointe…
New
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44316
|
2026-05-29 03:31 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
605
|
6.5 |
MEDIUM
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose as…
New
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44317
|
2026-05-29 03:30 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
606
|
5.3 |
MEDIUM
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscrip…
New
|
CWE-362 CWE-820
Race Condition Missing Synchronization
|
CVE-2026-44318
|
2026-05-29 03:24 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
607
|
7.3 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbi…
New
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2026-44320
|
2026-05-29 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
608
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argume…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9446
|
2026-05-29 03:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
609
|
8.1 |
HIGH
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immedia…
New
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2026-9095
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
610
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urlj…
New
|
CWE-601
Open Redirect
|
CVE-2026-45307
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|