|
191
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of t…
New
|
CWE-401 CWE-404
Missing Release of Memory after Effective Lifetime Improper Resource Shutdown or Release
|
CVE-2026-9572
|
2026-05-28 23:32 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
192
|
5.3 |
MEDIUM
Network
|
rexxars
|
eventsource-encoder
|
eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage b…
New
|
CWE-93 CWE-113
CRLF Injection HTTP Response Splitting
|
CVE-2026-44214
|
2026-05-28 23:30 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193
|
- |
|
-
|
-
|
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.
More precise…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9828
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194
|
6.8 |
MEDIUM
Local
|
-
|
-
|
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV fil…
New
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-9673
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer ove…
New
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-9605
|
2026-05-28 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can …
New
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-9581
|
2026-05-28 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197
|
7.5 |
HIGH
Network
|
archive\
|
\
|
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.
_read_tar() reads each entry's payload with $handle->read($$data, $block), …
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-9538
|
2026-05-28 23:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-8362
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199
|
3.1 |
LOW
Network
|
-
|
-
|
Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
New
|
CWE-22
Path Traversal
|
CVE-2026-49009
|
2026-05-28 23:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
New
|
-
|
CVE-2026-48902
|
2026-05-28 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|