CWE-404
CVEs classified under CWE-404, newest first.
82 CVEsRSS
CVE-2026-90582Medium· 5.3PoCA vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0
A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consum…
CVE-2026-90576Low· 3.3PoCA security vulnerability has been detected in GPAC up to f1219cde
A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The…
CVE-2026-90573Low· 3.3PoCA vulnerability was identified in GPAC up to f1219cde
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is …
CVE-2026-90485Medium· 5.5PoCA flaw has been found in IOBit Uninstaller 15.5.0.11
A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attac…
CVE-2026-41869Critical· 9.1Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.2…
CVE-2026-86515Medium· 4.3PoCA security vulnerability has been detected in vgmstream up to r2117
A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource c…
CVE-2026-86511Medium· 5.3PoCA vulnerability was found in java-json-tools jackson-coreutils 2.0
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation res…
CVE-2026-86319Medium· 5.3PoCA vulnerability has been found in java-json-tools json-patch up to 1.13
A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Ha…
CVE-2026-84886Medium· 5.3A vulnerability was determined in simular-ai Agent-S up to 0.3.2
A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argum…
CVE-2026-82552Medium· 4.3A security vulnerability has been detected in Linux Foundation Magma 1.9.0
A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to …
CVE-2026-17610NoneIn SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service
In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for EFR32MG24 and EFR32MG26 devices running concurrent multiprotocol Zigbee and Thread.
CVE-2026-19382Low· 2.3A weakness has been identified in Almico Speedfan 4.52
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be exe…
CVE-2026-19362Medium· 5.3A vulnerability has been found in lmammino oidc-authorizer 0.4.0
A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the a…
CVE-2026-17500Medium· 5.3A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0
A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched …
CVE-2026-60397Medium· 4.3Vulnerability in Oracle GoldenGate (component: Admin Server Executable)
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-15276Low· 3.3A flaw has been found in pdeljanov Symphonia up to 0.6.0
A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has bee…
CVE-2026-59725High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform
Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Ty…
CVE-2026-14629Medium· 4.3A flaw has been found in RT-Thread up to 5.2.2
A flaw has been found in RT-Thread up to 5.2.2. Affected is the function read/write/sys_ioctl of the file components/lwp/lwp_syscall.c of the component Parameter Handler. Executing a manipulation can lead to divide by zero. The attack ma…
CVE-2026-14626Medium· 4.3A weakness has been identified in NousResearch hermes-agent up to 2026.4.30
A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes…
CVE-2026-14624Medium· 4.3A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1
A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The manipulation leads to denial of service. It is pos…
CVE-2026-14623Medium· 4.3A vulnerability was determined in omec-project amf up to 2.1.1
A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. Executing a manipulation can lead to denial of service. The attack may be …
CVE-2026-14618Medium· 4.3A vulnerability was detected in Open5GS up to 2.7.7
A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. The manipulation results in denial of service. The a…
CVE-2025-10998Low· 5.5Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
CVE-2025-10999Medium· 5.5Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
CVE-2025-11000Medium· 4.4Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
CVE-2026-13523Low· 3.3A weakness has been identified in GPAC up to 26.02.0
A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data. The attack needs to be…
CVE-2026-54280High· 7.5⚖ disputedAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar…
CVE-2026-8252Medium· 4.3A vulnerability was determined in Open5GS up to 2.7.7
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from rem…
CVE-2026-8268Medium· 4.3A vulnerability has been found in Open5GS up to 2.7.7
A vulnerability has been found in Open5GS up to 2.7.7. This issue affects the function OpenAPI_list_create of the component SMF. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disc…
CVE-2026-8267Medium· 4.3A flaw has been found in Open5GS up to 2.7.7
A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vsmf of the component SMF. This manipulation causes denial of service. The attack may be initiated remotely. The exploi…