Tagged “cve.org”
CVEs tagged cve.org, newest first.
18480 CVEsRSS
CVE-2026-90685Low· 2.8PoCA vulnerability has been found in GPAC up to f1219cde
A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is requi…
CVE-2026-90684Low· 2.8PoCA flaw has been found in GPAC up to f1219cde
A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable asserti…
CVE-2026-90683Low· 3.3PoCA vulnerability was detected in GPAC up to f1219cde
A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locall…
CVE-2026-90682Medium· 5.3PoCA security vulnerability has been detected in Matthias-Wandel jhead up to 3.3
A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG …
CVE-2026-90680Critical· 9.9A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/…
CVE-2026-90622Low· 3.3PoCA security flaw has been discovered in GNU libredwg 0.13.4
A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to …
CVE-2023-37252Low· 3.1PoCAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
CVE-2023-34854Medium· 6.6HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
CVE-2023-32778Low· 3.3An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1
An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
CVE-2023-28148High· 7.2A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
CVE-2023-24291Low· 2.9Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
CVE-2023-24287Low· 2.9Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.
CVE-2023-24285Low· 2.9Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
CVE-2023-24284Low· 2.9Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
CVE-2023-24035Low· 3.5An issue was discovered in Nagios XI before 5.9.3
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in t…
CVE-2023-24034Low· 3.1An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3
An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
CVE-2023-22632Low· 2.7PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
CVE-2023-22631Low· 2.7PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
CVE-2026-90688Medium· 6.5PoCA vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC
A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overf…
CVE-2026-90687Medium· 6.3PoCA vulnerability was determined in GPAC up to f1219cde
A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is poss…
CVE-2026-25832Low· 3.7In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
CVE-2025-26790Low· 3.7Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.
Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.
CVE-2023-50461High· 8.8An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured …
CVE-2023-50460Medium· 5.4An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3
An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any f…
CVE-2023-46273High· 8.8Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
CVE-2023-46035Medium· 5.9The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
CVE-2023-45858High· 8.6A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
CVE-2023-45023Medium· 4.2The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
CVE-2023-37366Low· 2.8An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…
CVE-2026-90702Critical· 9.1PoCA flaw has been found in D-Link DWR-M921 1.1.52
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…