|
111
|
6.1 |
MEDIUM
Adjacent
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against it…
New
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2026-42081
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.
New
|
-
|
CVE-2026-38931
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
- |
|
-
|
-
|
OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the …
New
|
-
|
CVE-2026-38930
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-1248
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
- |
|
-
|
-
|
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media…
New
|
-
|
CVE-2025-70116
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
- |
|
-
|
-
|
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mec…
New
|
-
|
CVE-2025-68712
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via …
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-12686
|
2026-05-28 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Account Manager for WooCom…
New
|
CWE-862
Missing Authorization
|
CVE-2022-41656
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
7.5 |
HIGH
Network
|
ibm
|
http_server
|
IBM HTTP Server 8.5, and 9.0
New
|
CWE-94
Code Injection
|
CVE-2026-9170
|
2026-05-28 02:07 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
9.8 |
CRITICAL
Network
|
microsoft
|
power_pages
|
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
New
|
CWE-77
Command Injection
|
CVE-2026-23652
|
2026-05-28 02:01 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|