Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28438
Total
2190
Critical
8535
High
8856
Medium
CVE ID Severity Score Description Published
CVE-2026-44323 MEDIUM 4.3 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler contains a nil-pointer dereference reachable from … May 27, 2026
CVE-2026-44322 HIGH 7.5 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a nil-pointer dereference when the … May 27, 2026
CVE-2026-44321 HIGH 7.5 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. … May 27, 2026
CVE-2026-44320 HIGH 7.3 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A … May 27, 2026
CVE-2026-44319 HIGH 7.5 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot … May 27, 2026
CVE-2026-44318 MEDIUM 6.5 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global … May 27, 2026
CVE-2026-44317 MEDIUM 6.5 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose … May 27, 2026
CVE-2026-44316 HIGH 7.5 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontrol/v1/sm-policies handler (HandleCreateSmPolicyRequest) panics with a nil-pointer dereference when … May 27, 2026
CVE-2026-44315 CRITICAL 9.4 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network … May 27, 2026
CVE-2026-42790 UNKNOWN Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. … May 27, 2026
CVE-2026-42459 UNKNOWN free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in … May 27, 2026
CVE-2026-42083 HIGH 8.2 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers … May 27, 2026
CVE-2026-42082 LOW 3.7 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules … May 27, 2026
CVE-2026-42081 MEDIUM 6.1 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received … May 27, 2026
CVE-2026-38945 HIGH 7.8 Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the … May 27, 2026
CVE-2026-38931 MEDIUM 5.4 A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload. May 27, 2026
CVE-2026-38930 UNKNOWN OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into … May 27, 2026
CVE-2025-70116 UNKNOWN A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile … May 27, 2026
CVE-2025-68712 UNKNOWN SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric … May 27, 2026
CVE-2022-41656 MEDIUM 4.3 Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from … May 27, 2026
CVE-2026-9712 UNKNOWN When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). … May 27, 2026
CVE-2026-9674 MEDIUM 4.3 A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds. May 27, 2026
CVE-2026-6957 HIGH 8.0 Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of … May 27, 2026
CVE-2026-49103 UNKNOWN Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi. May 27, 2026
CVE-2026-49102 MEDIUM 6.1 Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a … May 27, 2026