Total CVEs

125,862

Critical Severity

2,275

High Severity

7,879

Last 7 Days

1,162
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 8,726 CVEs
CVE-2026-7536 MEDIUM - 5.3

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsf_sess_add_by_ip_address of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a manipulation of the argument ipv4Addr can lead to denial of service. The attack can be launched remo...

Published: May 01, 2026
Source: NVD
CVE-2026-7535 MEDIUM - 4.3

A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c of the file /namf-comm/v1/ue-contexts/{ueContextId}/transfer-update. Performing a manipulation of the argument ueContextId results in...

Published: May 01, 2026
Source: NVD
CVE-2026-7518 MEDIUM - 4.3

A flaw has been found in Open5GS up to 2.7.7. This issue affects the function amf_namf_callback_handle_sdm_data_change_notify of the file /namf-callback/v1/{id}/sdmsubscription-notify of the component AMF SBI Endpoint. This manipulation of the argument changeItem.newValue causes denial of service. T...

Published: May 01, 2026
Source: NVD
CVE-2026-5404 MEDIUM - 4.7

K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Published: May 01, 2026
Source: NVD
CVE-2026-22726 MEDIUM - 5.0

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reac...

Vendor: CloudFoundry Foundation
Product: Routing release, CF Deployment
Published: May 01, 2026
Source: NVD
CVE-2026-7510 MEDIUM - 6.3

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been public...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7508 MEDIUM - 6.3

A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the attack is possible. Th...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7502 MEDIUM - 5.4

A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remote...

Published: Apr 30, 2026
Source: NVD
CVE-2026-6542 MEDIUM - 6.5

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

Published: Apr 30, 2026
Source: NVD
CVE-2026-40687 MEDIUM - 4.8

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

Vendor: Exim
Product: Exim
Published: Apr 30, 2026
Source: NVD
CVE-2026-40685 MEDIUM - 6.5

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

Vendor: Exim
Product: Exim
Published: Apr 30, 2026
Source: NVD
CVE-2026-40684 MEDIUM - 5.9

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Vendor: Exim
Product: Exim
Published: Apr 30, 2026
Source: NVD
CVE-2026-3345 MEDIUM - 6.5

IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

Published: Apr 30, 2026
Source: NVD
CVE-2026-2311 MEDIUM - 6.4

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

Published: Apr 30, 2026
Source: NVD
CVE-2026-1577 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.

Published: Apr 30, 2026
Source: NVD
CVE-2025-36335 MEDIUM - 6.2

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.

Vendor: IBM
Product: watsonx.data intelligence
Published: Apr 30, 2026
Source: NVD
CVE-2025-36180 MEDIUM - 5.3

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

Vendor: IBM
Product: watsonx.data
Published: Apr 30, 2026
Source: NVD
CVE-2025-36122 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.

Vendor: IBM
Product: Db2
Published: Apr 30, 2026
Source: NVD
CVE-2025-14688 MEDIUM - 5.3

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.

Vendor: IBM
Product: Db2
Published: Apr 30, 2026
Source: NVD
CVE-2026-6539 MEDIUM - 4.4

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through communit...

Published: Apr 30, 2026
Source: NVD