|
61
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontrol/v1/sm-policies handler (HandleCreateSmPolicyRequest) panics with a nil-pointe…
New
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44316
|
2026-05-29 03:31 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
62
|
6.5 |
MEDIUM
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose as…
New
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44317
|
2026-05-29 03:30 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
63
|
5.3 |
MEDIUM
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscrip…
New
|
CWE-362 CWE-820
Race Condition Missing Synchronization
|
CVE-2026-44318
|
2026-05-29 03:24 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
64
|
7.3 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbi…
New
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2026-44320
|
2026-05-29 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
65
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argume…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9446
|
2026-05-29 03:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
66
|
8.1 |
HIGH
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immedia…
New
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2026-9095
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
67
|
5.0 |
MEDIUM
Network
|
-
|
-
|
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46561
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
68
|
- |
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
New
|
CWE-326 CWE-329 CWE-353 CWE-759 CWE-916
Inadequate Encryption Strength Not Using a Random IV with CBC Mode Missing Support for Integrity Check Use of a One-Way Hash without a Salt Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-45787
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
69
|
- |
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
New
|
CWE-94 CWE-732 CWE-940
Code Injection Incorrect Permission Assignment for Critical Resource Improper Verification of Source of a Communication Channel
|
CVE-2026-45353
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
70
|
8.7 |
HIGH
Network
|
-
|
-
|
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45348
|
2026-05-29 03:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|