|
3291
|
5.5 |
MEDIUM
Local
|
libsixel saitoha
|
libsixel
|
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
|
CWE-617
Reachable Assertion
|
CVE-2022-27938
|
2026-04-24 23:12 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3292
|
5.5 |
MEDIUM
Local
|
libsixel saitoha
|
libsixel
|
stb_image.h (también se conoce como el cargador de imágenes de stb) versión 2.19, como es usado en libsixel y otros productos, presenta una aserción alcanzable en la función stbi__create_png_image_raw
|
CWE-617
Reachable Assertion
|
CVE-2022-27938
|
2026-04-24 23:12 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3293
|
7.2 |
HIGH
Network
|
mintplexlabs
|
anythingllm
|
A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper handling of user inpu…
|
CWE-29
Path Traversal: '\..\filename'
|
CVE-2026-5627
|
2026-04-24 22:57 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3294
|
7.5 |
HIGH
Network
|
nestjs
|
nest
|
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() recurses once per m…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-40879
|
2026-04-24 22:46 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3295
|
5.0 |
MEDIUM
Network
|
openfga
|
helm_charts openfga
|
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requ…
|
CWE-706 CWE-863
Use of Incorrectly-Resolved Name or Reference Incorrect Authorization
|
CVE-2026-41131
|
2026-04-24 22:44 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3296
|
7.8 |
HIGH
Local
|
saitoha
|
libsixel
|
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation res…
|
CWE-119 CWE-121 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow Out-of-bounds Write
|
CVE-2025-9300
|
2026-04-24 22:44 |
2025-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3297
|
7.8 |
HIGH
Local
|
saitoha
|
libsixel
|
Se encontró una vulnerabilidad en saitoha libsixel hasta la versión 1.10.3. Este problema afecta a la función sixel_debug_print_palette del archivo src/encoder.c del componente img2sixel. La manipula…
|
CWE-119 CWE-121 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow Out-of-bounds Write
|
CVE-2025-9300
|
2026-04-24 22:44 |
2025-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3298
|
8.8 |
HIGH
Local
|
packagekit_project
|
packagekit
|
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41651
|
2026-04-24 22:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3299
|
7.5 |
HIGH
Network
|
coturn_project
|
coturn
|
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * wit…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2026-40613
|
2026-04-24 22:41 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3300
|
7.5 |
HIGH
Network
|
protocol
|
libp2p
|
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A m…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-35405
|
2026-04-24 22:37 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|