|
631
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.War…
New
|
-
|
CVE-2026-9096
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
- |
|
-
|
-
|
Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and pa…
New
|
-
|
CVE-2026-9097
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
- |
|
-
|
-
|
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnReques…
New
|
-
|
CVE-2026-9098
|
2026-05-29 03:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
- |
|
-
|
-
|
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe wi…
New
|
CWE-22 CWE-269 CWE-284 CWE-732
Path Traversal Improper Privilege Management Improper Access Control Incorrect Permission Assignment for Critical Resource
|
CVE-2026-9789
|
2026-05-29 02:58 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNo…
New
|
CWE-20 CWE-617 CWE-755
Improper Input Validation Reachable Assertion Improper Handling of Exceptional Conditions
|
CVE-2026-44319
|
2026-05-29 02:50 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a n…
New
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44322
|
2026-05-29 02:37 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
4.3 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-1248
|
2026-05-29 02:19 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
6.6 |
MEDIUM
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-48918
|
2026-05-29 02:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-9818
|
2026-05-29 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the arg…
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9531
|
2026-05-29 02:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|