|
491
|
3.3 |
LOW
Local
|
nextcloud
|
approval
|
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can req…
New
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-45277
|
2026-06-4 02:36 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
492
|
6.1 |
MEDIUM
Network
|
nextcloud
|
user_oidc
|
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses …
New
|
CWE-601
Open Redirect
|
CVE-2026-45278
|
2026-06-4 02:34 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
493
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGA…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-37226
|
2026-06-4 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
494
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() re…
New
|
CWE-617
Reachable Assertion
|
CVE-2026-37228
|
2026-06-4 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
495
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., a single 0x00 b…
New
|
CWE-617
Reachable Assertion
|
CVE-2026-37229
|
2026-06-4 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
496
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIG…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-37230
|
2026-06-4 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
497
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ E42_SETUP_REQUESTs, the 16-bit counter wraps around and produces duplicate…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-37231
|
2026-06-4 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
498
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_id against itself (m…
New
|
CWE-617
Reachable Assertion
|
CVE-2026-37233
|
2026-06-4 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
499
|
7.5 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function valid_xapp_id() only checks that the value is within the…
New
|
CWE-284
Improper Access Control
|
CVE-2026-37235
|
2026-06-4 02:15 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
500
|
6.5 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config…
New
|
CWE-22
Path Traversal
|
CVE-2026-45279
|
2026-06-4 02:15 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|