5.4

CVSS3.1

CVE-2026-7500 - Org.keycloak.keycloak-services: improper access control on keycloak server when the account account…

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()`…

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 5, 2026, 3 a.m.

0.0

CVE-2026-36340 -

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

📅 Published: April 30, 2026, midnight 🔄 Last Modified: April 30, 2026, 3:37 p.m.

0.0

CVE-2026-36759 -

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

📅 Published: April 30, 2026, midnight 🔄 Last Modified: April 30, 2026, 4:03 p.m.

7.5

CVSS3.1

CVE-2025-56568 -

Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial of service via specially crafted NGAP messages containing malformed length fields in protocol config…

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 4, 2026, 8 p.m.

7.0

CVSS3.1

CVE-2026-31787 - xen/privcmd: fix double free via VMA splitting

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on a privcmd mapping, the kernel splits the VMA via __split_vm…

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 4, 2026, 7:46 a.m.

7.5

CVSS3.1

CVE-2025-46115 -

An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 4, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2026-36959 - Unrestricted Brute‑Force Login on U‑SPEED N300 Router

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized…

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 5, 2026, 3 a.m.

7.5

CVSS3.1

CVE-2026-36958 - Denial of Service via HTTP Flood on U‑SPEED N300 Router

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the r…

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 5, 2026, 3 a.m.

7.5

CVSS3.1

CVE-2026-36957 - Denial of Service via Resource Exhaustion on Dbit N300 T1 Pro Router

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffe…

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 5, 2026, 2:59 a.m.

8.8

CVSS3.1

CVE-2026-36956 - Cross‑Site Request Forgery in Dbit N300 T1 Pro Router Web Management

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An …

📅 Published: April 30, 2026, midnight 🔄 Last Modified: May 5, 2026, 12:09 a.m.
Total resulsts: 348200
Page 97 of 34,820
« previous page » next page
Filters