6.9

CVSS4.0

CVE-2026-40249 - free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subs…

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization err…

📅 Published: April 16, 2026, 9:59 p.m. 🔄 Last Modified: April 16, 2026, 9:59 p.m.

8.7

CVSS4.0

CVE-2026-40248 - free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic In…

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for creating or updating Traffic Influence Subscriptions checks whether the influenceId path segment equals subs-to-notify, but does not return after sending the HTTP 404 res…

📅 Published: April 16, 2026, 9:57 p.m. 🔄 Last Modified: April 16, 2026, 11:30 p.m.

8.7

CVSS4.0

CVE-2026-40247 - free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptio…

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for reading Traffic Influence Subscriptions checks whether the influenceId path segment equals subs-to-notify, but does not return after sending the HTTP 404 response when va…

📅 Published: April 16, 2026, 9:54 p.m. 🔄 Last Modified: April 16, 2026, 11:30 p.m.

8.7

CVSS4.0

CVE-2026-40246 - free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscript…

free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the handler for deleting Traffic Influence Subscriptions checks whether the influenceId path segment equals subs-to-notify, but does not return after sending the HTTP 404 response when v…

📅 Published: April 16, 2026, 9:40 p.m. 🔄 Last Modified: April 16, 2026, 11:30 p.m.

7.5

CVSS3.1

CVE-2026-40170 - ngtcp2 has a qlog transport parameter serialization stack buffer overflow

ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transp…

📅 Published: April 16, 2026, 9:34 p.m. 🔄 Last Modified: April 16, 2026, 11:30 p.m.

8.8

CVSS4.0

CVE-2026-40308 - My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog

My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for unauthenticated users, passes user-supplied arguments through parse_str() without validation, allowing injection of arbitrary parameters including a sit…

📅 Published: April 16, 2026, 9:30 p.m. 🔄 Last Modified: April 16, 2026, 9:30 p.m.

8.7

CVSS4.0

CVE-2026-39313 - MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP tra…

mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the HTTP transport concatenates request body chunks into a string with no size limit. Although a maxMessageSize configuration value exists, it is never enf…

📅 Published: April 16, 2026, 9:24 p.m. 🔄 Last Modified: April 16, 2026, 9:24 p.m.

4.9

CVSS3.1

CVE-2026-34164 - Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService

Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive information including personal data (PII), citizen identifier…

📅 Published: April 16, 2026, 9:17 p.m. 🔄 Last Modified: April 16, 2026, 9:17 p.m.

4.8

CVSS3.1

CVE-2026-33472 - Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-3…

Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hardcodes the URI scheme based on port number, causin…

📅 Published: April 16, 2026, 9:12 p.m. 🔄 Last Modified: April 16, 2026, 9:12 p.m.

8.7

CVSS4.0

CVE-2026-40900 - DataEase has SQL Injection via Stacked Queries

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation that the input is a single SELECT statement. Combi…

📅 Published: April 16, 2026, 8:53 p.m. 🔄 Last Modified: April 16, 2026, 11 p.m.
Total resulsts: 344930
Page 2 of 34,493
« previous page » next page
Filters