Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,879
Quick preset (or use dates below)
Clear Filters
Showing 661 - 680 of 3,522 CVEs
CVE-2026-9093 CRITICAL - 9.8

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudie...

Published: May 28, 2026
Source: NVD
CVE-2026-9092 CRITICAL - 9.1

Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even inc...

Published: May 28, 2026
Source: NVD
CVE-2026-9090 CRITICAL - 9.1

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-co...

Published: May 28, 2026
Source: NVD
CVE-2026-38707 CRITICAL - 9.8

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-38704 CRITICAL - 9.8

A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devic...

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-38703 CRITICAL - 9.8

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target device...

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-38702 CRITICAL - 9.8

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target device...

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-24444 CRITICAL - 9.8

SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the rec...

Vendor: SDMC Technology Co., Ltd
Product: NE6037
Published: May 28, 2026
Source: NVD
CVE-2026-9813 CRITICAL - 9.9

FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specifie...

Vendor: flowintel
Product: flowintel
Published: May 28, 2026
Source: NVD
CVE-2026-46195 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd before proving a DACL header fits insid...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46185 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than size...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46155 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire O...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46137 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context. To avoid any data races, the socket lock needs to be held with bh_lock_sock(). If the socket is...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46135 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), but it does so without serializing against target-side qu...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46119 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treated as an error code by ceph_handle_auth_r...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46115 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable biovec_phys_mergeable() is used by the request merge, DMA mapping, and integrity merge paths to decide if two physically contiguous bvec segments can be coalesced into one. It curren...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-4408 CRITICAL - 9.0

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without p...

Published: May 28, 2026
Source: NVD
CVE-2026-32999 CRITICAL - 9.0

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.

Vendor: WebPros
Product: Comet Backup
Published: May 28, 2026
Source: NVD
CVE-2026-46621 CRITICAL - 9.1

Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-46562 CRITICAL - 9.8

Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub