Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42775
Total
3467
Critical
12772
High
12580
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-30063 | UNKNOWN | — | An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query. | Aug 27, 2026 |
| CVE-2026-30062 | HIGH | 7.5 | An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU. | Aug 27, 2026 |
| CVE-2026-30060 | UNKNOWN | — | An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration. | Aug 27, 2026 |
| CVE-2026-30059 | UNKNOWN | — | An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message. | Aug 27, 2026 |
| CVE-2026-30058 | UNKNOWN | — | Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 27, 2026 |
| CVE-2026-30057 | HIGH | 7.5 | An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request. | Aug 27, 2026 |
| CVE-2026-30056 | HIGH | 7.5 | A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted … | Aug 27, 2026 |
| CVE-2026-30051 | UNKNOWN | — | An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request. | Aug 27, 2026 |
| CVE-2026-30050 | HIGH | 7.5 | An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request. | Aug 27, 2026 |
| CVE-2026-30047 | HIGH | 7.5 | A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE … | Aug 27, 2026 |
| CVE-2026-30046 | HIGH | 7.5 | A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE … | Aug 27, 2026 |
| CVE-2026-30045 | UNKNOWN | — | An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET … | Aug 27, 2026 |
| CVE-2026-26899 | UNKNOWN | — | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands … | Aug 27, 2026 |
| CVE-2026-26897 | UNKNOWN | — | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the … | Aug 27, 2026 |
| CVE-2026-26459 | UNKNOWN | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data. | Aug 27, 2026 |
| CVE-2026-26457 | UNKNOWN | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when processing COAP messages containing options with zero length. | Aug 27, 2026 |
| CVE-2026-26456 | UNKNOWN | — | A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the … | Aug 27, 2026 |
| CVE-2026-26453 | UNKNOWN | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the … | Aug 27, 2026 |
| CVE-2026-26452 | UNKNOWN | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers. | Aug 27, 2026 |
| CVE-2026-19889 | HIGH | 8.2 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, … | Aug 27, 2026 |
| CVE-2026-19854 | MEDIUM | 6.1 | When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and … | Aug 27, 2026 |
| CVE-2026-16279 | CRITICAL | 9.3 | An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some … | Aug 27, 2026 |
| CVE-2026-11754 | MEDIUM | 5.3 | Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned … | Aug 27, 2026 |
| CVE-2026-11747 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: … | Aug 27, 2026 |
| CVE-2025-62343 | LOW | 3.1 | HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session … | Aug 27, 2026 |