Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

30387
Total
2427
Critical
9093
High
9467
Medium
CVE ID Severity Score Description Published
CVE-2026-6842 LOW 2.5 A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for … Apr 22, 2026
CVE-2026-6023 HIGH 8.1 In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state … Apr 22, 2026
CVE-2026-6022 HIGH 7.5 In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum … Apr 22, 2026
CVE-2026-40542 HIGH 7.3 Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. … Apr 22, 2026
CVE-2026-6840 MEDIUM 5.5 Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0. Apr 22, 2026
CVE-2026-6839 MEDIUM 6.6 Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source … Apr 22, 2026
CVE-2026-41667 MEDIUM 6.6 Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is … Apr 22, 2026
CVE-2026-41666 MEDIUM 6.6 Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version … Apr 22, 2026
CVE-2026-41665 MEDIUM 6.1 Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior … Apr 22, 2026
CVE-2026-41664 MEDIUM 6.6 Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is … Apr 22, 2026
CVE-2026-40450 MEDIUM 6.6 Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected … Apr 22, 2026
CVE-2026-40449 MEDIUM 6.6 Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version … Apr 22, 2026
CVE-2026-40448 MEDIUM 5.3 Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is … Apr 22, 2026
CVE-2026-22754 HIGH 7.5 Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet … Apr 22, 2026
CVE-2026-22753 HIGH 7.5 Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter … Apr 22, 2026
CVE-2026-22748 MEDIUM 5.3 Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling … Apr 22, 2026
CVE-2026-22747 MEDIUM 6.8 Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for … Apr 22, 2026
CVE-2026-22746 LOW 3.7 Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's … Apr 22, 2026
CVE-2026-40451 MEDIUM 6.1 DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's … Apr 22, 2026
CVE-2026-6835 MEDIUM 6.1 The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, … Apr 22, 2026
CVE-2026-6834 MEDIUM 6.5 The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method. Apr 22, 2026
CVE-2026-6833 MEDIUM 6.5 The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. Apr 22, 2026
CVE-2026-6416 LOW 2.7 Tanium addressed an uncontrolled resource consumption vulnerability in Interact. Apr 22, 2026
CVE-2026-6408 LOW 2.7 Tanium addressed an information disclosure vulnerability in Tanium Server. Apr 22, 2026
CVE-2026-6392 LOW 2.7 Tanium addressed an information disclosure vulnerability in Threat Response. Apr 22, 2026