|
241
|
6.1 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacke…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-40919
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bou…
New
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2026-40918
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
5.0 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious …
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-40917
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
5.0 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-40916
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-40915
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
8.7 |
HIGH
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description)…
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-35569
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
5.3 |
MEDIUM
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type …
New
|
CWE-200 CWE-863
Information Exposure Incorrect Authorization
|
CVE-2026-33888
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
3.7 |
LOW
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/r…
New
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-33877
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
7.8 |
HIGH
Local
|
-
|
-
|
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in loa…
New
|
CWE-416
Use After Free
|
CVE-2026-33023
|
2026-04-16 05:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
7.1 |
HIGH
Local
|
-
|
-
|
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling…
New
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2026-33019
|
2026-04-16 05:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|