|
521
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, an…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-7424
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-7425
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-7426
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
4.8 |
MEDIUM
Network
|
-
|
-
|
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpos…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-1858
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
5.5 |
MEDIUM
Local
|
-
|
-
|
HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6868
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
5.5 |
MEDIUM
Local
|
-
|
-
|
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-7375
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
7.4 |
HIGH
Network
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
New
|
CWE-59
Link Following
|
CVE-2026-41882
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully pr…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22740
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
3.1 |
LOW
Network
|
-
|
-
|
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
* the ap…
New
|
CWE-524
Use of Cache Containing Sensitive Information
|
CVE-2026-22741
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22745
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|