|
51
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to referen…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44794
|
2026-05-29 03:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to a…
New
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-44796
|
2026-05-29 03:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
8.5 |
HIGH
Network
|
-
|
-
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44797
|
2026-05-29 03:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
7.1 |
HIGH
Network
|
-
|
-
|
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the cu…
New
|
CWE-471 CWE-749
Modification of Assumed-Immutable Data (MAID) Exposed Dangerous Method or Function
|
CVE-2026-44798
|
2026-05-29 03:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
4.9 |
MEDIUM
Network
|
synology
|
surveillance_station
|
Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with adm…
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-47269
|
2026-05-29 03:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
2.7 |
LOW
Network
|
synology
|
surveillance_station
|
Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administra…
New
|
CWE-281
Improper Preservation of Permissions
|
CVE-2024-47270
|
2026-05-29 03:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
4.9 |
MEDIUM
Network
|
synology
|
surveillance_station
|
Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privi…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-47271
|
2026-05-29 03:37 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
2.7 |
LOW
Network
|
synology
|
surveillance_station
|
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to …
New
|
CWE-863
Incorrect Authorization
|
CVE-2024-47272
|
2026-05-29 03:37 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Da…
New
|
CWE-20 CWE-209
Improper Input Validation Information Exposure Through an Error Message
|
CVE-2026-42459
|
2026-05-29 03:35 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
9.4 |
CRITICAL
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44315
|
2026-05-29 03:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|