| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images with malicious XMP profiles to crash applications that process them using ImageMagick. |
| Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected. |
| Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community EditionĀ 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. |
| ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder-based policy restrictions, causing ImageMagick to process formats the administrator intended to block. |
| ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger the out-of-bounds heap write through crafted input to crash the server, causing a denial of service. |
| OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter. |
| libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can cause a denial of service. |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0. |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0. |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0. |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0. |
| Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1. |
| Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0. |
| Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRentCar vikrentcar allows Reflected XSS.This issue affects VikRentCar: from n/a through 1.4.7. |
| Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: from n/a through 2.4.1. |
| Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled. |
| In the Linux kernel, the following vulnerability has been resolved:
net: hsr: fix potential OOB access in supervision frame handling
Ensure the entire TLV header is linearized before access by adding
sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this,
a truncated frame could cause an out-of-bounds access. |
| In the Linux kernel, the following vulnerability has been resolved:
ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
rss_prepare_get() allocates the indirection table and hash key buffer
via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them.
If get_rxfh() fails, the function returns an error without freeing
the allocation. |
| In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; Issue ID: MSV-9571. |