<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Denial of Service (DoS)</title>
  <link>https://cvedaily.com/pages/tags/dos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/dos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Denial of Service (DoS)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-8888 – Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8888</guid>
    <pubDate>Wed, 03 Jun 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-8888</strong></p>
  <p>Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-36605 – Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36605</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-36605</strong></p>
  <p>Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low number of crafted incomplete HTTP requests, causing a persistent crash that requires physical power cycling to recover.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37462 – An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37462</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37462</strong></p>
  <p>An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44545 – daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44545</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44545</strong></p>
  <p>daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-37460 – Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRout...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37460</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-37460</strong></p>
  <p>Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-70101 – An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70101</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-70101</strong></p>
  <p>An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculatio…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-70100 – A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70100</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-70100</strong></p>
  <p>A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime cr…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60477 – A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60477</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60477</strong></p>
  <p>A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9516 – Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9516</guid>
    <pubDate>Wed, 03 Jun 2026 01:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9516</strong></p>
  <p>Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.  To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-14036 – Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-14036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-14036</guid>
    <pubDate>Tue, 02 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-14036</strong></p>
  <p>Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC packets to exhaust CPU resources in the affected process, causing further SDC mes…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-14036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8035 – Improper input validation in the NI-PAL kernel driver may allow a local authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8035</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8035</strong></p>
  <p>Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48597 – Allocation of Resources Without Limits or Throttling vulnerability in elixir-tes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48597</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48597</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint.  Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing request to a BEAM atom via String.to_atom(uri.scheme) with no allow-list validation. BEAM atoms are never garbage-collected and the atom table is bounded (approxi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48594 – Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48594</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48594</strong></p>
  <p>Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies.  When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are decompressed eagerly with no size limit. The decompress_body/2 function in lib/t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4479 – Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4479</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4479</strong></p>
  <p>Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the Medibus interface. Attackers can transmit malformed data to overload the internal processor, gradually disrupting device operation over several hours and causing loss of dat…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25724 – Dräger Infinity M300 patient worn monitors with software version VG2.x and earli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25724</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25724</strong></p>
  <p>Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to the hospital or Infinity Network to repeatedly trigger device reboots until the device enters a fail state requiring manual restart. Attackers can exploit this vulnerability to cause loss of wireless network connectivity, t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25723 – Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper inp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25723</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25723</strong></p>
  <p>Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the Medibus interface. Attackers can overload the internal processor with malformed data to trigger a warm restart, causing ventilation pressure to drop to ambient le…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25721 – Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25721</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25721</strong></p>
  <p>Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly trigger device reboots by sending malicious requests over the Infinity Network. Attackers can exploit this vulnerability to force the device into a fail state requiring manual restart, causing loss of wire…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1871 – TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1871</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1871</strong></p>
  <p>TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request.  Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition.  This…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45686 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45686</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45686</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45685 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45685</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45685</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44367 – Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44367</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44367</strong></p>
  <p>Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3871 – A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3871</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3871</strong></p>
  <p>A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3870 – A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3870</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3870</strong></p>
  <p>A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10295 – A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10295</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10295</strong></p>
  <p>A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service. The attack requires a local approach. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28578 – In multiple functions of DevicePolicyManagerService.java, there is a possible de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28578</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28578</strong></p>
  <p>In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0085 – In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0085</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0085</strong></p>
  <p>In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0080 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0080</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0080</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0079 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0079</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0079</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0074 – In getPreferredSize of LauncherProcessImageListener.kt, there is a possible deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0074</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0074</strong></p>
  <p>In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service  due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0070 – In multiple functions of DevicePolicyManagerService.java, there is a possible wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0070</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0070</strong></p>
  <p>In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0069 – In verifySignature of ApkChecksums.java, there is a possible way to cause a cras...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0069</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0069</strong></p>
  <p>In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0067 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0067</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0067</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0060 – In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0060</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0060</strong></p>
  <p>In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0052 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0052</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0052</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0051 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0051</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0051</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0044 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0044</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0044</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0043 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0043</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0043</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0042 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0042</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0042</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0041 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0041</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0041</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0040 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0040</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0040</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0039 – In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0039</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0039</strong></p>
  <p>In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0018 – In multiple functions of AccessibilityManagerService.java, there is a possible p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0018</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0018</strong></p>
  <p>In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48648 – In isSameApp of NotificationManagerService.java, there is a possible persistent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48648</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48648</strong></p>
  <p>In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49140 – Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49140</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49140</strong></p>
  <p>Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events with omitted or invalid declared sizes to trigger simultaneous large media down…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70099 – A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70099</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70099</strong></p>
  <p>A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesystem image with malformed directory entries. During directory iteration, the code may fail to validate the directory entry pointer before accessing the name_len field, resulting in a segmentation fault.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43958 – A flaw was found in rrdcached, a component of rrdtool. A local attacker with acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43958</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43958</strong></p>
  <p>A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10118 – A flaw was found in Poppler's Splash backend. A remote attacker could exploit th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10118</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10118</strong></p>
  <p>A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60495 – A segmentation violation in the gf_media_get_color_info function (/media_tools/i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60495</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60495</strong></p>
  <p>A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60486 – A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60486</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60486</strong></p>
  <p>A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60485 – A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/iso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60485</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60485</strong></p>
  <p>A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60483 – A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60483</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60483</strong></p>
  <p>A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60481 – A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descripto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60481</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60481</strong></p>
  <p>A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55664 – A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55664</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55664</strong></p>
  <p>A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49361 – Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49361</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49361</strong></p>
  <p>Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service.  This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0.  Users are rec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48208 – An improper neutralization of active SVG content in OTRS or ((OTRS)) Community E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48208</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48208</strong></p>
  <p>An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the co…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20456 – In wlan STA driver, there is a possible system crash due to a missing bounds che...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20456</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20456</strong></p>
  <p>In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10190 – A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10190</guid>
    <pubDate>Sun, 31 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10190</strong></p>
  <p>A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8594 – Text::LineFold versions through 2019.001 for Perl duplicate the output based on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8594</guid>
    <pubDate>Sat, 30 May 2026 16:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8594</strong></p>
  <p>Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.  Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just the segment.  A side effect of this is that the full input can be duplicated for each segment.  Besi…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25426 – WinMTR 0.91 contains a denial of service vulnerability that allows attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25426</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25426</strong></p>
  <p>WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers can create a specially crafted input file with 238 bytes of data to trigger a buffer overflow condition that causes the application to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25423 – Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25423</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25423</strong></p>
  <p>Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10117 – A weakness has been identified in Open5GS up to 2.7.7. This issue affects the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10117</guid>
    <pubDate>Sat, 30 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10117</strong></p>
  <p>A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. It is best practice to apply a patch to resolve this issue.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10116 – A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10116</guid>
    <pubDate>Sat, 30 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10116</strong></p>
  <p>A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of service. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is the recommen…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10115 – A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10115</guid>
    <pubDate>Sat, 30 May 2026 11:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10115</strong></p>
  <p>A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit is publicly available and might be used. It is advisable to implement a patch to correct this issue.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10113 – A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10113</guid>
    <pubDate>Sat, 30 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10113</strong></p>
  <p>A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. The manipulation results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used. A patch should be applied to remediate this issue.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46527 – cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46527</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46527</strong></p>
  <p>cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose value parses to no valid IP segments. The code path then executes get_client_ip(), which calls front() on an empty std::vec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44420 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44420</guid>
    <pubDate>Fri, 29 May 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44420</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process (remote DoS) and may be exploitable for code execution because it corrupts heap memory. This vulne…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46344 – liboqs is a C-language cryptographic library that provides implementations of po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46344</guid>
    <pubDate>Fri, 29 May 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46344</strong></p>
  <p>liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a correctly-sized signature buffer for the declared algorithm but a public key whose OID bytes (pk[0..3]) reference…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44518 – liboqs is a C-language cryptographic library that provides implementations of po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44518</guid>
    <pubDate>Fri, 29 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44518</strong></p>
  <p>liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the expected signature size for the given parameter set, the implementation does not…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45615 – mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45615</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45615</strong></p>
  <p>mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to validate the required bytes before extracting the Most Significant Bit (MSB). Th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9509 – An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9509</guid>
    <pubDate>Fri, 29 May 2026 13:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9509</strong></p>
  <p>An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10028 – A flaw was found in glib-networking. A remote attacker can exploit this vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10028</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10028</strong></p>
  <p>A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traver…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39929 – Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39929</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39929</strong></p>
  <p>Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49094 – Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49094</guid>
    <pubDate>Thu, 28 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49094</strong></p>
  <p>Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kibana will consume excessive CPU and memory resources while processing the request. This results in Kibana becoming unavail…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46843 – Vulnerability in Oracle REST Data Services (component: Core).  Supported version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46843</guid>
    <pubDate>Thu, 28 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46843</strong></p>
  <p>Vulnerability in Oracle REST Data Services (component: Core).  Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST D…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46835 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46835</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46835</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46834 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46834</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46834</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46829 – Vulnerability in Oracle REST Data Services (component: Mongoapi).  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46829</guid>
    <pubDate>Thu, 28 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46829</strong></p>
  <p>Vulnerability in Oracle REST Data Services (component: Mongoapi).  Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42400 – Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42400</guid>
    <pubDate>Thu, 28 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42400</strong></p>
  <p>Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and CPU resource consumption that can result in a Kibana instance becoming unresponsive or crashing.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42399 – Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42399</guid>
    <pubDate>Thu, 28 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42399</strong></p>
  <p>Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression containing deeply chained function calls. The resulting data structure grows without bound, exhaustin…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35266 – Vulnerability in Oracle REST Data Services (component: Core).  Supported version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35266</guid>
    <pubDate>Thu, 28 May 2026 21:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35266</strong></p>
  <p>Vulnerability in Oracle REST Data Services (component: Core).  Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33464 – Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33464</guid>
    <pubDate>Thu, 28 May 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33464</strong></p>
  <p>Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process to exhaust available resources and become unresponsive to all users until the service recovers or is restarted.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45044 – RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45044</guid>
    <pubDate>Thu, 28 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45044</strong></p>
  <p>RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e.g., glibc), the handler invokes a fixed 60-second CPU profiling operation (dump_cpu_pprof_for(Dura…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44796 – Nautobot is a Network Source of Truth and Network Automation Platform. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44796</guid>
    <pubDate>Thu, 28 May 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44796</strong></p>
  <p>Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the find field in combination with the use_regex flag. This vulnerability is fixed in 2.4.33 and 3.1.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48525 – PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48525</guid>
    <pubDate>Thu, 28 May 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48525</strong></p>
  <p>PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detache…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42250 – bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42250</guid>
    <pubDate>Thu, 28 May 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42250</strong></p>
  <p>bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9803 – A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9803</guid>
    <pubDate>Thu, 28 May 2026 06:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9803</strong></p>
  <p>A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing the server to return an HTTP 500 error and resulting in a Denial of Service (DoS…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9801 – A flaw was found in Keycloak. A remote attacker with high privileges, such as a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9801</guid>
    <pubDate>Thu, 28 May 2026 06:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9801</strong></p>
  <p>A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryEr…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9759 – ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9759</guid>
    <pubDate>Wed, 27 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9759</strong></p>
  <p>ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1402 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1402</guid>
    <pubDate>Wed, 27 May 2026 19:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1402</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44521 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44521</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44521</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through a crafted target file hash. Successful exploitation can lead to unauthorized dat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44378 – Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44378</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44378</strong></p>
  <p>Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibits indefinite length encodings. This vulnerability is fixed in 3.12.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44328 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44328</guid>
    <pubDate>Wed, 27 May 2026 17:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44328</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF after the type-guarded async release, even though AN-typed nodes are constructed without a UPF object. As a result, a singl…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8180 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8180</guid>
    <pubDate>Wed, 27 May 2026 14:17:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8180</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8175 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8175</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8175</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7528 – IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to unco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7528</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7528</strong></p>
  <p>IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7254 – IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7254</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7254</strong></p>
  <p>IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6053 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6053</guid>
    <pubDate>Wed, 27 May 2026 14:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6053</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6051 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6051</guid>
    <pubDate>Wed, 27 May 2026 14:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6051</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4410 – IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM Web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4410</guid>
    <pubDate>Wed, 27 May 2026 14:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4410</strong></p>
  <p>IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47104 – libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47104</guid>
    <pubDate>Wed, 27 May 2026 14:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47104</strong></p>
  <p>libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47104">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
