|
991
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
Update
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-43859
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
992
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
Update
|
CWE-193
Off-by-one Error
|
CVE-2026-43860
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
993
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
Update
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-43861
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
994
|
3.7 |
LOW
Network
|
-
|
-
|
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
Update
|
CWE-843
Type Confusion
|
CVE-2026-43862
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
995
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
Update
|
CWE-253
Incorrect Check of Function Return Value
|
CVE-2026-43863
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
996
|
2.5 |
LOW
Local
|
-
|
-
|
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-43864
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
997
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-31205
|
2026-05-6 04:44 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
998
|
8.1 |
HIGH
Network
|
-
|
-
|
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data received from the server response, enabling client-sid…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42471
|
2026-05-6 04:39 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
999
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42472
|
2026-05-6 04:39 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1000
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42473
|
2026-05-6 04:39 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|