|
2501
|
8.8 |
HIGH
Network
|
ibm
|
i
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-7870
|
2026-06-17 00:00 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2502
|
8.1 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7787
|
2026-06-16 23:58 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2503
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2025-55652
|
2026-06-16 23:56 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2504
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-55660
|
2026-06-16 23:56 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2505
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2025-55661
|
2026-06-16 23:56 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2506
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55663
|
2026-06-16 23:56 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2507
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
CWE-295
Improper Certificate Validation
|
CVE-2026-9258
|
2026-06-16 23:53 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2508
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
CWE-295
Improper Certificate Validation
|
CVE-2026-9259
|
2026-06-16 23:53 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2509
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-9260
|
2026-06-16 23:53 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2510
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-9261
|
2026-06-16 23:53 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|