|
441
|
8.2 |
HIGH
Network
|
-
|
-
|
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via c…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40022
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
442
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41409
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
443
|
8.8 |
HIGH
Network
|
-
|
-
|
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInput…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40858
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
444
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.
Apache Camel's camel-coap component is vulnerable to Camel message …
New
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-33453
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
445
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
New
|
CWE-248
Uncaught Exception
|
CVE-2026-5937
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
446
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
New
|
CWE-691
Insufficient Control Flow Management
|
CVE-2026-5938
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
447
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
New
|
CWE-416
Use After Free
|
CVE-2026-5939
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
448
|
7.8 |
HIGH
Local
|
-
|
-
|
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
New
|
CWE-416
Use After Free
|
CVE-2026-5940
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
449
|
7.8 |
HIGH
Local
|
-
|
-
|
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during inte…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-5941
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
450
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
New
|
CWE-416
Use After Free
|
CVE-2026-5942
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|