|
921
|
9.8 |
CRITICAL
Network
|
jizhicms
|
jizhicms
|
Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
Update
|
CWE-89
SQL Injection
|
CVE-2025-50229
|
2026-04-28 03:24 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
922
|
7.5 |
HIGH
Network
|
zfnd
|
zebra-network zebrad
|
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra wo…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-40881
|
2026-04-28 03:24 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
923
|
4.3 |
MEDIUM
Network
|
ibm
|
guardium_data_protection
|
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.
Update
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-1272
|
2026-04-28 03:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
924
|
4.9 |
MEDIUM
Network
|
ibm
|
guardium_data_protection
|
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
Update
|
CWE-840
Business Logic Errors
|
CVE-2026-1274
|
2026-04-28 03:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
925
|
6.5 |
MEDIUM
Network
|
ibm
|
db2
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
Update
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-1352
|
2026-04-28 03:22 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
926
|
6.6 |
MEDIUM
Local
|
samsung
|
one
|
Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE
Affected version is prior …
Update
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-6839
|
2026-04-28 03:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
927
|
6.6 |
MEDIUM
Local
|
samsung
|
one
|
Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes.
Affected version is prior to commit 1.30.0.
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41667
|
2026-04-28 03:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
928
|
6.1 |
MEDIUM
Local
|
samsung
|
one
|
Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors.
Affected version is prior to commit…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41665
|
2026-04-28 03:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
929
|
6.6 |
MEDIUM
Local
|
samsung
|
one
|
Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation.
Affected version is prior to commit 1.30.0.
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41666
|
2026-04-28 03:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
930
|
6.6 |
MEDIUM
Local
|
samsung
|
one
|
Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes.
Affected version is prior to commit 1.30.0.
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41664
|
2026-04-28 03:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|