By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 60 of 86
- CVE-2026-47734MEDIUM 5.7
Dulwich is a Python library used by Git servers to handle code push operations. A vulnerability in versions before 1.2.5 allows an attacker with push access to craft a specially designed small Git package that tricks the server into allocating hundreds of megabytes of memory based on false size declarations in the package header. This memory exhaustion attack can degrade or crash the server, denying legitimate developers access to the repository.
- CVE-2026-48187MEDIUM 5.7
OTRS has a vulnerability in its email handling system that allows authenticated users to trigger excessive resource allocation on the web server, potentially causing it to crash or become unresponsive. An attacker with valid login credentials can exploit this through user interaction to exhaust server resources, resulting in denial of service. This is not a critical vulnerability but poses a meaningful availability risk to organizations relying on OTRS for ticketing operations.
- CVE-2026-48189MEDIUM 5.7
OTRS has released a security update addressing an input validation flaw in its Customer Backend module that allows authenticated users to bypass group-based access controls and view customer information they shouldn't have access to. The vulnerability requires that the CustomerGroupSupport feature is both enabled and actively used within the deployment. While the flaw is rated medium severity, it poses a direct confidentiality risk for organizations managing sensitive customer data through OTRS ticketing systems.
- CVE-2026-48210MEDIUM 5.7
OTRS 2026.3.1 has a configuration issue where ticket forwarding automatically marks internal information as visible to customers, and administrators cannot turn this off through the user interface. This means sensitive ticket details that should remain internal can unintentionally become visible to external customers, creating a data leakage risk.
- CVE-2026-49220MEDIUM 5.7
Jellyfin, a self-hosted open-source media server, contains a cross-site scripting (XSS) vulnerability that allows unprivileged users to inject malicious JavaScript into an administrative account. An attacker can craft a special Client header value during the authentication process that, when viewed by an admin in the dashboard, executes arbitrary code in that admin's browser session. This could grant the attacker the ability to perform administrative actions, modify system settings, or access sensitive information without explicit authorization. The vulnerability affects Jellyfin versions prior to 10.11.9.
- CVE-2026-49993MEDIUM 5.7
Nuxt's build tools (rspack-builder and webpack-builder) contain a flaw that allows attackers to steal source code during local development. If a developer runs the Nuxt dev server on a network-accessible address and then visits a malicious website, that site can intercept and exfiltrate the developer's source code. This is a regression—an incomplete patch for an earlier vulnerability—affecting versions 3.15.4 through 3.21.6 and 4.0.0 through 4.4.6. The risk is primarily to development environments, not production systems.
- CVE-2026-58024MEDIUM 5.7
A MediaWiki vulnerability allows authenticated users to access sensitive information they shouldn't be able to see. The flaw is in the user rights API component and requires an attacker to be logged in and interact with a user interface element. While the exposure is limited to confidential data (no data modification or system disruption), it represents a meaningful privacy and compliance risk because sensitive administrative or user information could be leaked to unauthorized individuals.
- CVE-2026-58026MEDIUM 5.7
A vulnerability in MediaWiki allows authenticated users to view sensitive information they shouldn't have access to through a flaw in the parser component. An attacker needs a valid login and user interaction to exploit this, limiting the attack surface but still representing a meaningful information disclosure risk in environments where many users have accounts.
- CVE-2026-61432MEDIUM 5.7
PraisonAI versions before 1.6.78 contain a path traversal weakness in their FastContext feature. When the system executes file-related tools like file reading or directory listing, it does not properly validate absolute file paths or path sequences that use '../' to step backward through directories. This means an attacker with access to the application could craft requests or manipulate the AI model to read files outside the intended workspace directory, potentially exposing sensitive data stored on the server.
- CVE-2026-10222MEDIUM 5.6
A vulnerability exists in NousResearch's hermes-agent software that allows attackers to inject malicious code through improper sanitization of environment variables. The flaw resides in the configuration parsing logic and can be exploited remotely, though successful exploitation requires substantial technical knowledge and effort. While a public exploit exists, the attack surface is limited by high complexity requirements. This is a medium-severity issue affecting versions up to 2026.4.30.
- CVE-2026-10540MEDIUM 5.6
Control-M/Enterprise Manager versions 9.0.20.x and earlier use cryptographic hashing methods that do not meet modern security standards for protecting stored user passwords. If an attacker gains access to the credential database—through a breach, misconfiguration, or physical access—they could potentially recover plaintext passwords offline using computational attacks. This is a local-origin threat that requires the attacker to already have obtained the password hash file, but once in hand, the weak protection mechanism makes password recovery feasible without further network access to the system.
- CVE-2026-11941MEDIUM 5.6
Cloudflare's Quiche QUIC library contains two use-after-free vulnerabilities in its C FFI (Foreign Function Interface) layer. When applications call the quiche_connection_id_iter_next or quiche_conn_retired_scid_next functions, these functions return a pointer to connection ID data that has already been freed from memory. This is a memory safety issue that primarily affects custom applications that directly use Quiche's C bindings—a relatively small subset compared to Rust consumers. The good news is the FFI layer is disabled by default and requires explicit build-time opt-in.
- CVE-2026-13524MEDIUM 5.6
CherryHQ's cherry-studio application contains an authorization flaw in its MCP OAuth callback mechanism that could allow remote attackers to bypass access controls. The vulnerability exists in the OAuth callback handler where improper validation of the 'code' parameter fails to enforce proper authorization checks. An attacker would need to craft a malicious request, but exploitation requires high technical complexity and specific conditions. Versions up to 1.9.6 are affected.
- CVE-2026-13529MEDIUM 5.6
YzmCMS versions up to 7.5 contain a SQL injection vulnerability in the installation script that can be triggered by manipulating the siteurl parameter. While the flaw allows an attacker to read, modify, or delete database contents, exploiting it requires navigating non-trivial technical barriers and is not straightforward to execute. The vendor has not responded to early disclosure attempts, leaving users without an official patch timeline.
- CVE-2026-13543MEDIUM 5.6
Documenso versions up to 2.11.0 contain an authentication flaw in their Google OAuth login implementation that could allow an attacker to bypass or manipulate the authentication process. The vulnerability exists in the OAuth callback URL handling logic and requires specific technical conditions to exploit, making it moderately difficult to execute. While a public exploit exists, successful attacks would still demand significant effort and precision from an attacker.
- CVE-2026-13588MEDIUM 5.6
PcapPlusPlus, a packet processing library version 25.05, contains a vulnerability in its TLS handshake processing that allows an attacker to cause a heap-based buffer overflow by manipulating the handshake version parameter. While the vulnerability is accessible over the network, exploiting it requires significant technical effort and specific conditions. The flaw could potentially allow an attacker to read sensitive memory, modify data, or disrupt application availability, though practical exploitation remains constrained by the high complexity barrier.
- CVE-2026-13589MEDIUM 5.6
PcapPlusPlus version 25.05 contains a heap buffer overflow vulnerability in its Telnet packet parsing logic. When processing specially crafted Telnet subnegotiation commands, the vulnerable code can write beyond allocated memory boundaries. While remote exploitation is possible without authentication, the attack requires careful crafting and succeeds only under specific conditions, making opportunistic attacks less likely. A public exploit exists, increasing practical risk.
- CVE-2026-13590MEDIUM 5.6
A heap-based buffer overflow vulnerability has been identified in seladb PcapPlusPlus version 25.05, specifically within the Modbus Protocol Handler component. When a specially crafted packet with a manipulated length argument is processed by the pcpp::ModbusLayer::getLength function, it can cause a buffer overflow in heap memory. An unauthenticated attacker on the network can trigger this condition, though significant technical knowledge and specific packet construction are required to exploit it successfully. The vulnerability enables attackers to leak sensitive memory contents, corrupt data, or potentially crash the application.
- CVE-2026-14355MEDIUM 5.6
PHP versions before specific patch levels contain a flaw in how they allocate memory for AES key-wrap-with-padding operations within the OpenSSL extension. When processing encrypted keys, the application reserves too little memory for the output, allowing OpenSSL to write beyond these bounds. This corrupts internal heap structures and causes the application to crash. The vulnerability requires specific conditions to trigger—it is not a remote code execution—but does enable a network attacker to cause denial of service on affected systems.
- CVE-2026-14609MEDIUM 5.6
CVE-2026-14609 is a session fixation vulnerability in SourceCodester CET Automated Grading System with AI Predictive Analytics version 1.0. An attacker can remotely manipulate an unknown processing component to hijack or lock a user's session, gaining unauthorized access to the account without needing to know the victim's password. The attack is complex to execute, requiring significant technical skill, but public exploit code now exists, raising the practical risk despite the moderate CVSS rating.
- CVE-2026-14627MEDIUM 5.6
NousResearch's hermes-agent, a tool used for building agent applications, contains an authentication bypass vulnerability in its Discord platform integration. The flaw exists in code responsible for verifying whether a Discord user is allowed to interact with the agent. An attacker can exploit this remotely by manipulating the authentication check, gaining unauthorized access to agent functionality. While the technical difficulty is high and exploitation requires specific knowledge, the vendor has not provided patches or meaningful engagement on the issue since disclosure.
- CVE-2026-1764MEDIUM 5.6
GNOME localsearch, a desktop search indexing tool, contains a memory safety flaw in its MP3 metadata parser. When a specially crafted MP3 file with ID3v2.4 tags is processed, the software fails to properly validate tag boundaries before reading heap memory. This can crash the indexing process or leak sensitive data from the application's memory space. The vulnerability requires local access and user interaction—a user must open or index a malicious MP3 file—but the consequences can include service disruption and unintended data exposure.
- CVE-2026-1765MEDIUM 5.6
GNOME localsearch contains a heap buffer overflow vulnerability in its MP3 file processing component. When a user opens a specially crafted MP3 file, the application can crash unexpectedly. There is also a potential risk that sensitive data from system memory could be exposed during the crash. This is a locally-triggered vulnerability—an attacker must first convince a user to open a malicious file rather than launching an attack remotely over the network.
- CVE-2026-1766MEDIUM 5.6
A heap buffer overflow vulnerability exists in GNOME localsearch's MP3 file parser. When processing maliciously crafted MP3 files with corrupted ID3v2.3 comment tags, the tracker-extract-mp3 component can crash or leak sensitive data from system memory. An attacker needs local access and user interaction (opening or processing the file) to trigger the flaw. This is a moderate-risk issue affecting Linux systems running affected GNOME versions.
- CVE-2026-1767MEDIUM 5.6
GNOME's localsearch application contains a heap buffer overflow flaw in its MP3 file processor that can be triggered when a specially crafted MP3 file with malformed ID3 tags is scanned or indexed. An attacker who can place a malicious MP3 on a system would cause the application to crash (denial of service) or potentially leak sensitive information from memory. This is not a remote code execution vulnerability and requires local access and user interaction to exploit.
- CVE-2026-2604MEDIUM 5.6
A vulnerability in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host system. The flaw stems from inconsistent validation logic: when contacts are created or modified, malicious URIs containing directory traversal sequences (like "../") are accepted without proper checks. When those contacts are later deleted, a less strict validation routine processes the URI and actually follows the traversal, deleting files the attacker specified. This could affect critical system files, including Flatpak override configurations that control sandboxing rules.
- CVE-2026-28322MEDIUM 5.6
SolarWinds Database Performance Analyzer contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the application. When a user views a page containing the injected script, the malicious code executes in their browser with their privileges. This vulnerability requires an attacker to have authenticated access and user interaction to exploit, limiting but not eliminating the risk in environments where internal users have administrative permissions.
- CVE-2026-6899MEDIUM 5.6
A flaw in S2OPC library's CycloneCrypto cryptographic wrapper causes the system to stop checking certificate revocation status after finding the first Certificate Revocation List (CRL) from a Certificate Authority. If additional CRLs exist for the same CA, they are ignored. This means a client or server using a revoked certificate could establish an OPC UA connection when it should be rejected, potentially allowing unauthorized communication with compromised credentials.
- CVE-2020-9711MEDIUM 5.5
Adobe Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier contain a flaw that allows an attacker to read sensitive data from a computer's memory when a user opens a specially crafted PDF file. The vulnerability does not allow attackers to modify files or crash the application, but it does expose information that should remain private. An attacker would need to trick someone into opening a malicious PDF to exploit this issue.
- CVE-2020-9713MEDIUM 5.5
CVE-2020-9713 is a memory disclosure vulnerability in Adobe Acrobat and Reader that allows an attacker to read sensitive data from a victim's computer. The flaw occurs when the application improperly accesses memory outside intended boundaries while processing a malicious PDF file. An attacker must trick a user into opening a crafted document to exploit it—there is no remote attack vector. While the vulnerability cannot directly crash the application or alter files, it can expose confidential information such as cached credentials, encryption keys, or other sensitive data resident in memory at the time of exploitation.
- CVE-2025-24165MEDIUM 5.5
A permissions enforcement gap in macOS allows applications to trigger unexpected system shutdowns. The vulnerability stems from insufficient access controls that permit an app—without requiring special privileges or admin credentials—to initiate a termination condition. Apple addressed this by reinforcing permission checks across the affected operating system versions. The attack requires user interaction (such as running or interacting with a malicious app), but does not require the user to have special knowledge of the vulnerability.
- CVE-2025-24268MEDIUM 5.5
CVE-2025-24268 is a medium-severity vulnerability in macOS that stems from inadequate validation of directory paths during parsing. An attacker with local access and user-level privileges could potentially exploit this weakness to read sensitive user data on an affected system. Apple has resolved this issue in macOS Sequoia 15.4 by implementing stricter path validation controls.
- CVE-2025-30431MEDIUM 5.5
CVE-2025-30431 is a medium-severity vulnerability in Apple macOS that allows a malicious application already running on a user's computer to access private information. The flaw stems from inadequate validation checks in the operating system. Because an attacker must first get a malicious app onto the system and have it execute with user-level privileges, the real-world risk depends heavily on how the app gets installed—whether through social engineering, supply-chain compromise, or user mistake. Apple has patched this across three recent macOS versions.
- CVE-2025-30459MEDIUM 5.5
CVE-2025-30459 is a privacy vulnerability affecting macOS that could allow an app to access sensitive user data without appropriate restrictions. Apple addressed this by removing the vulnerable code path in macOS Sequoia 15.4. The issue requires local access and an already-installed application to exploit, limiting its immediate risk to targeted or supply-chain scenarios.
- CVE-2025-36372MEDIUM 5.5
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a flaw that allows authenticated database users to access sensitive information from internal monitoring and event tables they should not be able to view. An attacker with valid database credentials could exploit this to extract confidential data, though they cannot modify information or disrupt service. This affects Db2 installations on Linux, Unix, and Windows platforms, including Db2 Connect Server deployments.
- CVE-2025-43278MEDIUM 5.5
CVE-2025-43278 is a local privilege escalation vulnerability in macOS Sequoia that allows an application to access protected user data through improper symlink handling. An attacker with local access and user interaction can exploit this to read sensitive files that should be restricted. The vulnerability requires the user to take an action (such as opening a file or interacting with an app), but does not require administrator privileges. Apple has addressed this in macOS Sequoia 15.4 with improved symlink validation logic.
- CVE-2025-43339MEDIUM 5.5
A sandbox isolation weakness in macOS Tahoe allows a malicious app running with user privileges to read sensitive user data that should have been protected. The vulnerability does not allow the attacker to modify data or crash the system, only to view it. Apple has patched this in macOS Tahoe 26.1 by strengthening sandbox restrictions.
- CVE-2025-46293MEDIUM 5.5
CVE-2025-46293 is a local privilege escalation vulnerability in macOS that allows installed applications to read protected user data through improper symlink handling. An attacker with local access and the ability to run an app on the target system could potentially bypass file access restrictions and view sensitive files. The vulnerability requires local presence and user-level privileges to exploit, making it a concern primarily for multi-user systems or scenarios where an attacker can install malicious software. Apple has resolved this with improved symlink validation in macOS Sequoia 15.4.
- CVE-2025-46313MEDIUM 5.5
CVE-2025-46313 is a logging defect in macOS Tahoe that could allow a third-party application to access sensitive user information that should have been redacted from system logs. The vulnerability stems from incomplete data redaction in logging routines, enabling an app to read information it should not have access to. This is a local attack vector requiring user interaction, such as installing or running the vulnerable application.
- CVE-2025-48648MEDIUM 5.5
CVE-2025-48648 is a denial-of-service vulnerability in Android's NotificationManagerService that allows a local attacker to exhaust system resources and crash the notification service. An attacker with basic user privileges can trigger this flaw without user interaction, causing persistent disruption to the device's notification functionality.
- CVE-2025-5085MEDIUM 5.5
The WP Nano AD plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability affecting versions 1.31 and earlier. An authenticated administrator can inject malicious scripts through the 'blogrole_link' parameter that persist in the database and execute in the browsers of users who view affected pages. The vulnerability is limited to WordPress multisite installations or those with the 'unfiltered_html' capability disabled, which narrows its real-world scope but makes it critical for affected deployments.
- CVE-2025-55641MEDIUM 5.5
GPAC MP4Box version 2.4 contains a flaw that can crash when processing a specially crafted MP4 video file. A user who opens a malicious MP4 file in MP4Box will experience a denial-of-service condition, rendering the tool unavailable. This is a local vulnerability requiring user interaction—the attacker must trick someone into opening a malicious file.
- CVE-2025-55643MEDIUM 5.5
CVE-2025-55643 is a denial-of-service vulnerability in GPAC MP4Box v2.4 that occurs when the application processes a specially crafted MP4 file. The flaw stems from a NULL pointer dereference in the TrackWriter handling code, which causes the application to crash. An attacker can exploit this by distributing a malicious MP4 file that, when opened by a user, terminates the MP4Box process. This is a local attack requiring user interaction—the victim must open the file—but no special privileges are needed.
- CVE-2025-55644MEDIUM 5.5
A memory safety flaw in GPAC MP4Box version 2.4 allows an attacker to crash the application by submitting a specially crafted MP4 video file. The vulnerability stems from improper handling of memory references in the scene graph processing code, where the application attempts to access memory that has already been freed. An attacker would need local access or the ability to trick a user into opening a malicious MP4 file.
- CVE-2025-55645MEDIUM 5.5
CVE-2025-55645 is a memory safety issue in GPAC MP4Box v2.4 that can be triggered by opening a specially crafted MP4 file. The vulnerability exists in code that handles digital rights management (DRM) protection information within MP4 containers. An attacker who creates a malicious MP4 file can cause the application to crash, denying service to legitimate users. The vulnerability requires local file system access and user interaction to trigger—an attacker cannot exploit it remotely over the network.
- CVE-2025-55647MEDIUM 5.5
GPAC MP4Box version 2.4 contains a flaw that causes the application to consume excessive memory and crash when processing a maliciously crafted MP4 file. An attacker can exploit this by distributing a specially designed MP4 that triggers an out-of-memory condition during the CENC (Common Encryption) PSSH (Protection System Specific Header) insertion process, effectively denying service to users attempting to process the file.
- CVE-2025-55648MEDIUM 5.5
GPAC's MP4Box version 2.4 contains a memory handling defect that can be triggered by opening a specially crafted MP4 media file. The vulnerability allows an attacker to crash the application, disrupting work for anyone using the tool to process or analyze video files. An attacker would need local access or the ability to deliver a malicious file to a target user, but no special privileges or complex exploitation steps are required once the file is opened.
- CVE-2025-55649MEDIUM 5.5
CVE-2025-55649 is a NULL pointer dereference vulnerability in GPAC MP4Box v2.4 that crashes the application when processing a maliciously crafted MP4 file. An attacker can trigger a denial-of-service condition by supplying a specially constructed media file, rendering the tool temporarily unavailable. This is a local attack that requires user interaction—the victim must open the malicious MP4 file—but does not require any elevated privileges.
- CVE-2025-55650MEDIUM 5.5
CVE-2025-55650 is a memory safety flaw in GPAC MP4Box v2.4 that occurs when the application processes a specially crafted MP4 file. The vulnerability causes the program to access memory that has already been freed (a 'use-after-free' condition), leading to a crash or denial of service. An attacker would need to trick a user into opening a malicious MP4 file, but no special privileges are required to exploit it.
- CVE-2025-55651MEDIUM 5.5
CVE-2025-55651 is a denial-of-service vulnerability in GPAC's MP4Box v2.4 that crashes the application when processing a specially crafted MP4 file. The flaw stems from the software attempting to access memory without first checking whether a critical pointer is valid. An attacker can exploit this by distributing a malformed MP4 file; if a user opens it with the vulnerable version, the application will crash. This is a local attack requiring user interaction—someone must open the malicious file—but no special privileges are needed.
- CVE-2025-55652MEDIUM 5.5
A memory corruption vulnerability exists in GPAC MP4Box version 2.4 that can be triggered by opening a specially crafted MP4 media file. The flaw is in code responsible for handling video codec configuration data, and exploiting it causes the application to crash, resulting in a denial of service. An attacker would need to trick a user into opening a malicious MP4 file locally on their system to trigger the vulnerability.
- CVE-2025-55660MEDIUM 5.5
CVE-2025-55660 is a stack overflow vulnerability in GPAC's MP4Box tool version 2.4. When a user opens a specially crafted MP4 video file, the vulnerability triggers a crash that renders the application temporarily unusable. An attacker would need to trick a user into opening a malicious MP4 file; the vulnerability does not allow remote code execution or data theft, but causes a denial of service. This is a localized threat affecting anyone using MP4Box to process untrusted video files.
- CVE-2025-55661MEDIUM 5.5
GPAC MP4Box version 2.4 contains a memory safety defect in its Opus audio parser that can be triggered by opening a specially crafted MP4 file. The flaw causes the application to crash, denying service to legitimate users. An attacker needs only local file access and user interaction (opening the file); no special privileges or network connectivity are required.
- CVE-2025-55663MEDIUM 5.5
GPAC MP4Box version 2.4 contains a crash vulnerability in how it processes MP4 video files. When a specially crafted MP4 file is opened, the application can crash due to improper memory handling in the track descriptor function. This is a local issue—an attacker would need to trick a user into opening a malicious file—but the impact is straightforward: service disruption. Media processing pipelines, automated transcoding systems, and any workflow relying on MP4Box could experience unexpected downtime.
- CVE-2025-55664MEDIUM 5.5
CVE-2025-55664 is a heap buffer overflow vulnerability in GPAC MP4Box version 2.4 that can be triggered when processing a specially crafted MP4 file. An attacker can exploit this by tricking a user into opening a malicious MP4 file, causing the application to crash or become unresponsive. This is a local, user-interaction-based attack that does not allow data theft or system compromise, but disrupts availability of the MP4Box tool.
- CVE-2025-59609MEDIUM 5.5
CVE-2025-59609 is a medium-severity information disclosure vulnerability affecting multiple Qualcomm wireless and audio chipset products. The flaw occurs when devices process Wi-Fi advertisement frames containing malformed MBSSID (Multiple BSSID) elements that are shorter than expected. An attacker with network proximity and valid credentials can craft these frames to trigger uninitialized memory access, potentially exposing sensitive data. The attack requires user interaction and specific network conditions to succeed, limiting its practical exploitability but still warranting prompt patching given the breadth of affected components.
- CVE-2025-59868MEDIUM 5.5
HCL Traveler for Microsoft Outlook contains a vulnerability that allows an authenticated attacker on the same system to read sensitive application data. An attacker with local access and valid user credentials could extract confidential information, which could then be leveraged for further attacks or cause unpredictable application behavior. This is a local privilege concern rather than a remote network attack.
- CVE-2025-60468MEDIUM 5.5
GPAC's MP4Box multimedia processing tool contains a memory safety defect that allows local users to crash the application by processing specially crafted video files. When MP4Box handles certain malformed MPEG-2 Transport Stream or MP4 files during filter cleanup operations, it attempts to access memory that has already been freed, triggering a denial-of-service condition. The flaw requires local system access and authenticated user privileges to exploit.
- CVE-2025-60471MEDIUM 5.5
GPAC Project's MP4Box, a widely-used multimedia processing tool, contains a use-after-free memory flaw in its filter configuration logic. When processing a specially crafted media file, the vulnerable code attempts to access memory that has already been freed, causing the application to crash. An attacker can exploit this by distributing a malicious media file that, when opened by a user, brings down MP4Box. This is a denial-of-service vulnerability—it doesn't steal data or grant unauthorized access, but it can disrupt workflows that depend on MP4Box for media processing.
- CVE-2025-60473MEDIUM 5.5
A flaw in GPAC Project's MP4Box media processing tool (versions before 26.02.0) can be triggered by opening a specially crafted media file, causing the application to crash. The vulnerability stems from improper handling of null pointers in the filter chain processing logic. While the crash itself doesn't lead to data theft or system compromise, it disrupts media processing workflows and could be weaponized in batch processing environments to degrade service availability.
- CVE-2025-60481MEDIUM 5.5
GPAC Project's MP4Box, a widely-used multimedia framework and command-line tool, contains a flaw in how it processes AC4 audio configuration data within media files. When a specially crafted AC4 file is opened, the application crashes due to a null pointer dereference—essentially trying to access memory that hasn't been properly initialized. This is a local denial-of-service vulnerability that requires user interaction (opening the malicious file) but could disrupt workflows involving media processing or transcoding pipelines.
- CVE-2025-60483MEDIUM 5.5
A flaw in GPAC Project/MP4Box's AC4 audio file parser can crash the application when processing a specially crafted audio file. An attacker would need to trick a user into opening a malicious AC4 file, causing the service to stop responding. This is a moderate-risk issue affecting organizations that rely on MP4Box for media processing or transcoding workflows.
- CVE-2025-60485MEDIUM 5.5
CVE-2025-60485 is a memory safety flaw in GPAC's MP4Box tool that causes the application to crash when processing a specially crafted MP4 media file. An attacker can exploit this by distributing a malicious MP4 that triggers the crash, disrupting service for anyone using MP4Box to process or analyze video files. The vulnerability requires local access and user interaction (opening or processing the file), so it is most relevant in environments where untrusted media files are routinely handled.
- CVE-2025-60486MEDIUM 5.5
A memory safety flaw in GPAC's MP4Box tool allows an attacker to crash the application by processing a specially crafted MPEG-2 video file. The vulnerability stems from improper memory management in the dasher_process function—specifically, the code attempts to access memory that has already been freed. An attacker with local file access can exploit this by distributing a malicious video file that, when opened in MP4Box, triggers the defect and renders the tool unusable. This is a denial-of-service issue rather than a path to code execution or data theft.
- CVE-2025-60495MEDIUM 5.5
GPAC's MP4Box, a widely-used multimedia toolkit, contains a memory safety flaw in its color information parsing logic. When MP4Box processes a specially crafted media file, the vulnerable code attempts to access memory in an unsafe manner, causing the application to crash. An attacker with the ability to supply a malicious file to a user or system running MP4Box can trigger this denial of service. This is a local impact issue—it requires user interaction to open the file—but the barrier to exploitation is low.
- CVE-2025-7005MEDIUM 5.5
Avast Antivirus and related Gen Digital products contain a flaw that causes their scanning engine to get stuck in an infinite loop when it encounters a specially crafted Windows executable file. An attacker who tricks a user into downloading a malformed file could crash the antivirus process, leaving the system temporarily unprotected. The vulnerability affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus across Windows, macOS, and Linux platforms. Gen Digital has fixed the issue in virus definition build VPS 25031700 and later, which rolls out automatically to all affected products through a shared update channel.
- CVE-2025-7006MEDIUM 5.5
Avast, AVG, and Norton antivirus products (along with Avast One and Avast Business variants) contain a use-after-free defect in their scanning engine that can crash the antivirus process when it encounters a specially crafted Windows PE file. This is a denial-of-service vulnerability affecting Windows, macOS, and Linux systems running virus definitions older than build 25022500. The vulnerability does not allow attackers to execute code or steal data, but disabling antivirus protection on a system could expose it to other threats.
- CVE-2025-7010MEDIUM 5.5
A stack overflow flaw in the antivirus engines used by Avast, AVG, Norton, and related products can crash the scanning process when it encounters a specially crafted PDF file. The vulnerability stems from unchecked recursive calls in the PDF parsing logic, which is shared across multiple Gen Digital consumer and business antivirus products via a centralized virus definition update channel. An attacker who can deliver a malformed PDF to a user could trigger a denial-of-service condition, temporarily disabling real-time malware protection until the antivirus process restarts.
- CVE-2025-70100MEDIUM 5.5
CVE-2025-70100 is a denial-of-service vulnerability in lwext4, a lightweight ext4 filesystem library. An attacker can craft a malicious ext4 filesystem image containing a zero logical block size that crashes any application using lwext4 to mount or process the image. The library fails to validate the block size parameter before performing arithmetic operations, leading to a divide-by-zero condition. While this vulnerability cannot be exploited for data theft or system compromise, it can disrupt services that depend on lwext4 for filesystem operations, such as embedded systems, recovery tools, or specialized storage applications.
- CVE-2025-7018MEDIUM 5.5
Avira Antivirus contains a vulnerability that can crash its scanning engine when it encounters a specially crafted Windows PE file. An attacker or malicious file could trigger this crash, temporarily disabling the antivirus protection on a system. The vulnerability affects Avira on Windows, macOS, and Linux platforms running engine versions before 8.3.70.64.
- CVE-2025-7019MEDIUM 5.5
A stack overflow flaw in antivirus scanning engines affects Avast, AVG, Norton, Avast One, and Avast Business products across Windows, macOS, and Linux. When these products scan a deliberately malformed Office Open XML file, the scanning process can crash, temporarily disabling antivirus protection on the affected machine. This is not a remote code execution or data theft risk, but it can leave systems unprotected during the outage. The vulnerability is fixed through a shared virus definition update; once your antivirus definitions reach build VPS 25020100 or later, you are protected.
- CVE-2025-71313MEDIUM 5.5
A memory allocation failure in the Linux kernel's PCI endpoint driver could cause the system to crash. When the kernel tries to create a work queue for handling PCI endpoint-to-endpoint communication, it doesn't properly check whether that operation succeeded. If memory is scarce and the allocation fails, the driver continues anyway and later attempts to use the non-existent queue, triggering a NULL pointer dereference that halts the affected system. The fix is straightforward: check whether the allocation succeeded before proceeding.
- CVE-2025-71314MEDIUM 5.5
A vulnerability in the Linux kernel's Panthor GPU driver can cause the graphics system to hang indefinitely when memory subsystem operations fail to complete. The issue arises because the driver lacks proper recovery mechanisms for stuck cache-flush operations. When a GPU memory flush times out, the driver now schedules a reset and recovers gracefully instead of hanging. This affects systems using Panthor-based GPUs (primarily ARM Mali GPUs in certain SoCs).
- CVE-2025-71315MEDIUM 5.5
A flaw exists in the Linux kernel's virtual kernel modesetting (vkms) driver related to how it manages display refresh timing. The vkms driver previously used its own custom timer implementation for vblank (vertical blank) events, which are critical synchronization points for display rendering. The vulnerability stems from inconsistencies between this custom implementation and the standard DRM (Direct Rendering Manager) vblank timer framework. When the kernel converts vkms to use the standardized DRM vblank timer, it removes the custom hrtimer mechanism, but improper handling during this transition can cause denial-of-service conditions—specifically, the system may become unresponsive or crash when display refresh timing is disrupted.
- CVE-2026-0018MEDIUM 5.5
CVE-2026-0018 is a denial-of-service vulnerability in Android's AccessibilityManagerService that allows a local attacker with user-level privileges to crash or hang the accessibility subsystem persistently. No special permissions, code execution, or user interaction are required to trigger the flaw—an authenticated local process can simply send malformed input to designated service functions that fail to properly validate their parameters. This could degrade or disable accessibility features for affected users.
- CVE-2026-0042MEDIUM 5.5
CVE-2026-0042 is a resource exhaustion vulnerability in Google Android's UBSan runtime component that allows a local attacker to cause a persistent denial of service. An attacker with basic user-level access can trigger the flaw without user interaction, exhausting system resources and rendering the device unavailable. The vulnerability does not enable unauthorized access or data theft—only availability disruption.
- CVE-2026-0043MEDIUM 5.5
CVE-2026-0043 is a medium-severity integer overflow vulnerability in Android's UBSan runtime library that can cause a persistent denial of service and local privilege escalation. The flaw resides in multiple functions within ubsan_throwing_runtime.cpp and requires only local access to exploit—no special privileges or user interaction are needed. Once triggered, the integer overflow can exhaust system resources or corrupt memory state, denying service to the affected device or enabling an attacker to elevate their privileges locally.
- CVE-2026-0060MEDIUM 5.5
CVE-2026-0060 is a local denial-of-service vulnerability in Android's graphics driver management system. A local attacker with basic user privileges can trigger a persistent crash condition in the GraphicsDriverEnableAngleAsSystemDriverController component, rendering the graphics subsystem unavailable without requiring elevated permissions or user interaction. The issue stems from improper state handling in the updateState method.
- CVE-2026-0064MEDIUM 5.5
CVE-2026-0064 is a resource exhaustion vulnerability affecting Google Android that allows a locally authenticated attacker to cause a persistent denial of service. The vulnerability exists in multiple code paths and requires only standard user privileges to trigger—no special permissions or user interaction are needed. Once exploited, the affected system can be rendered unresponsive or unstable until remediated.
- CVE-2026-0067MEDIUM 5.5
A logic error in Android's ubsan_throwing_runtime.cpp file can be exploited by a local attacker to permanently deny service to affected devices. The vulnerability requires only basic user-level permissions and no special interaction to trigger, making it a straightforward availability threat for any Android user or administrator managing affected deployments.
- CVE-2026-0069MEDIUM 5.5
CVE-2026-0069 is a resource exhaustion vulnerability in Android's signature verification code that allows a local attacker to crash the system without needing special privileges or user interaction. An attacker with basic local access can trigger excessive resource consumption in the APK checksum verification process, causing a denial of service.
- CVE-2026-0070MEDIUM 5.5
A flaw in Android's DevicePolicyManagerService allows a local attacker with standard user privileges to hide critical system packages through improper validation of input parameters. This creates a denial-of-service condition by making essential system components inaccessible, potentially rendering the device unstable or non-functional without requiring any special permissions or user interaction.
- CVE-2026-0074MEDIUM 5.5
CVE-2026-0074 is a denial-of-service vulnerability in Android's LauncherProcessImageListener component. An attacker with local system access can exhaust device resources through the getPreferredSize function, causing the launcher process to become unresponsive or crash. No special privileges or user interaction are required to trigger the flaw, making it a concern for multi-user devices and environments where untrusted code may run locally.
- CVE-2026-0079MEDIUM 5.5
CVE-2026-0079 is a denial-of-service vulnerability in Android's ubsan_throwing_runtime.cpp component. An integer overflow flaw allows a local attacker to crash or hang affected systems persistently without requiring elevated privileges or user interaction. The vulnerability resides in multiple functions within the runtime component responsible for undefined behavior sanitization, making it accessible to processes running with standard user permissions.
- CVE-2026-0085MEDIUM 5.5
A flaw in Android's contact data handling allows a local attacker to crash the system by inserting an unusually large contact name. The vulnerability exists in the DataRowHandler component, which fails to properly validate the size of contact name input before processing it. Because the attack requires only local access and no special privileges, any app on a compromised device could trigger the denial of service without user interaction.
- CVE-2026-0267MEDIUM 5.5
A vulnerability in Palo Alto Networks' GlobalProtect app for macOS allows a local user to read stored passcodes that protect critical app functions. Once an attacker learns these passcodes, they can disable, disconnect, or uninstall GlobalProtect even when the app's security policy would normally prevent such actions. This is a local-only risk that requires prior access to the affected macOS device.
- CVE-2026-0466MEDIUM 5.5
AMD uProf, a performance profiling tool, contains an access control vulnerability that allows a user with local system access to write data into memory regions normally reserved for the kernel. This weakness could crash the system or render it temporarily unavailable. The vulnerability requires an attacker to already have an account on the target system—it cannot be exploited remotely.
- CVE-2026-10688MEDIUM 5.5
A code injection vulnerability exists in ahujasid blender-mcp, a tool used for integrating Blender with model context protocol systems. An authenticated attacker can inject and execute arbitrary code by manipulating the 'code' parameter passed to the execute_blender_code function in the server. The vulnerability has been publicly disclosed and exploit code is available. The project uses rolling releases, making it difficult to identify fixed versions; however, the maintainers have been notified but have not yet responded with a patch or mitigation guidance.
- CVE-2026-11397MEDIUM 5.5
The WP Import Export Lite plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability affecting all versions up to 3.9.30. When administrators use the plugin's URL import feature, it first attempts a safe check to block requests to internal IP addresses. However, if that check fails or is bypassed, the plugin falls back to an unprotected method that sends requests directly to attacker-specified URLs without proper security controls. This allows a compromised administrator to make the WordPress server itself reach out to internal services, including cloud metadata endpoints that may expose sensitive credentials or configuration data.
- CVE-2026-11516MEDIUM 5.5
A buffer overflow vulnerability exists in UTT HiPER 2610G network devices through version 3.0.0-171107. An authenticated local attacker can send specially crafted input to the device's web interface to overflow a buffer and potentially read sensitive data, modify settings, or crash the device. The vulnerability resides in the NAT Static Map configuration feature and leverages improper bounds checking on the NatBinds parameter. Exploit code has been disclosed publicly.
- CVE-2026-11819MEDIUM 5.5
An Ansible module that retrieves passphrases from your operating system's credential storage (such as GNOME Keyring, macOS Keychain, or Windows Credential Manager) fails to hide those secrets in its output. When you run the module and register its result or use debug statements, the plaintext passphrase appears in logs and terminal output. This affects anyone using the keyring_info module who might store SSH key passphrases, database credentials, or other sensitive secrets—those credentials can leak into Ansible logs, fact caches, and AWX/Tower job histories.
- CVE-2026-11931MEDIUM 5.5
Kiro IDE versions before 0.11.133 store authentication tokens in a cache file that is readable by any user on the same machine. This happens because the file is created with overly permissive access settings (world-readable) instead of being restricted to the owner alone. An attacker with local access could read this cache file and potentially reuse the stored authentication token to impersonate the legitimate user. The vulnerability affects macOS and Linux systems and is resolved by upgrading to version 0.11.133 or later.
- CVE-2026-11968MEDIUM 5.5
TortoiseGit's Blame feature can be tricked into writing files to arbitrary locations on your system if you open a repository containing maliciously crafted filenames in the Git history. An attacker would need you to clone or open a malicious repository, but once you do, they could modify or create files on your computer without additional prompts. This is a local attack that requires user interaction but can have serious consequences for system integrity.
- CVE-2026-12162MEDIUM 5.5
Devolutions Remote Desktop Manager version 2026.2.8 contains a flaw in how it validates the identity of social login providers during the autofill process. An attacker can craft a malicious web entry pointing to a lookalike domain that mimics a legitimate social login provider. When a user interacts with this entry, the application fails to properly verify the provider's authenticity, potentially exposing stored social login credentials to the attacker. This is a social engineering vulnerability that exploits the trust users place in the autofill mechanism.
- CVE-2026-12163MEDIUM 5.5
Fortra's File Integrity Monitoring (FIM) solution, previously known as Tripwire Enterprise, has a stored cross-site scripting (XSS) vulnerability affecting versions before 9.4.0.1. An authenticated insider with elevated privileges can inject malicious script into configuration fields that later execute in a user's browser when viewing the Asset View UI component. The vulnerability requires both authentication and privilege escalation, limiting immediate risk but posing a real threat in environments where privileged users may be compromised or act maliciously.
- CVE-2026-12166MEDIUM 5.5
CVE-2026-12166 is a local denial-of-service vulnerability in Little Orbit's GFAC system driver (GFAC_Sys_x64.sys). An attacker with local access can send specially crafted requests that cause the driver to crash, disrupting system availability. This is not a remote vulnerability and does not involve data theft or system takeover—it focuses purely on making the system unavailable.
- CVE-2026-12223MEDIUM 5.5
Yealink SIP-T46U IP phones running firmware version 108.86.0.118 contain a command injection vulnerability in their web service that allows authenticated users on the local network to execute arbitrary commands by manipulating network parameters. An attacker with local network access and valid credentials can exploit this flaw to compromise the phone's integrity and confidentiality. A patched firmware version (108.87.0.23) is available, though the vendor notes the fix currently exists only in a technical support branch and has not been publicly released yet.
- CVE-2026-12444MEDIUM 5.5
A memory reading vulnerability exists in Google Chrome's Chromoting feature (Google's remote desktop tool) on Windows systems running versions prior to 149.0.7827.155. An attacker with local access to a machine can craft a malicious file that, when interacted with by a user, causes Chrome to read data outside its intended memory boundaries. This out-of-bounds read could expose sensitive information already present in the process's memory—such as cached authentication tokens, encryption keys, or other confidential data—without requiring elevated privileges or special system access. The vulnerability is not currently known to be exploited in the wild.
- CVE-2026-12480MEDIUM 5.5
Keras, a popular deep learning library, contains a flaw that allows attackers to read files from a victim's computer by crafting malicious model files. The vulnerability exists because Keras doesn't properly validate certain types of datasets when loading `.keras` or `.h5` model files. An attacker can create a specially crafted model that, when loaded by a user, silently reads sensitive files from the filesystem without the user's knowledge. This is a regression—a previously patched vulnerability was incompletely fixed, leaving the door open to the same attack vector.
- CVE-2026-1288MEDIUM 5.5
Autodesk Revit contains a vulnerability that can be triggered when converting a specially crafted RFA (Revit Family) file to FormIt format using the built-in "Convert RFA to FormIt" feature. A successful attack causes the application to crash, rendering it unavailable to the user. The vulnerability requires local access and user interaction—someone must explicitly open and convert a malicious file—but does not allow an attacker to steal data or modify files. The crash is a denial-of-service impact only.