|
521
|
9.1 |
CRITICAL
Network
|
teluu
|
pjsip
|
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message bod…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-41415
|
2026-04-29 03:30 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
7.5 |
HIGH
Network
|
teluu
|
pjsip
|
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymm…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41416
|
2026-04-29 03:30 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
9.8 |
CRITICAL
Network
|
dgraph
|
dgraph
|
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is …
Update
|
CWE-200
Information Exposure
|
CVE-2026-41492
|
2026-04-29 03:28 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
HID: apple: avoid memory leak in apple_report_fixup()
The apple_report_fixup() function was returning a
newly kmemdup()-allocated…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31520
|
2026-04-29 03:27 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
module: Fix kernel panic when a symbol st_shndx is out of bounds
The module loader doesn't check for bounds of the ELF section in…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-31521
|
2026-04-29 03:26 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
HID: magicmouse: avoid memory leak in magicmouse_report_fixup()
The magicmouse_report_fixup() function was returning a
newly kmem…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31522
|
2026-04-29 03:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
5.4 |
MEDIUM
Network
|
authlib
|
authlib
|
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vuln…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-41425
|
2026-04-29 03:18 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
6.1 |
MEDIUM
Network
|
pretalx
|
pretalx
|
pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by embedding malforme…
Update
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-41426
|
2026-04-29 03:17 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
3.1 |
LOW
Network
|
langchain
|
langchain-openai
|
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) va…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41488
|
2026-04-29 03:17 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
4.3 |
MEDIUM
Network
|
jpcert
|
logontracer
|
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.
Update
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-33566
|
2026-04-29 03:15 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|