Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-55647 — GPAC MP4Box Out-of-Memory Denial of Service

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2025-55645 — GPAC MP4Box Heap Buffer Overflow

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

| Memory Corruption
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2025-55644 — GPAC MP4Box Heap Use-After-Free

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

| Memory Corruption
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2025-55642 — GPAC MP4Box Floating Point Exception

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

| Memory Corruption
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2025-55641 — GPAC MP4Box NULL Pointer Dereference Denial of Service

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

| Memory Corruption
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2025-55643 — GPAC MP4Box: NULL Pointer Dereference Denial of Service

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
7.8 HIGH
CVE-2026-12191 — Comma AI Openpilot Pickle modeld.py pickle.loads deserialization

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation …

openpilot | Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
5.3 MEDIUM
CVE-2026-12190 — Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for cust…

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authori…

ai_workspace_app | Authorization
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
5.3 MEDIUM
CVE-2026-12189 — Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custo…

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in h…

bus_public_transit_app | Authorization
Jun 14, 2026 Jun 15, 2026
Jun 14, 2026
Jun 15, 2026
6.5 MEDIUM
CVE-2026-12188 — Grit42 Grit GritEntityController grit_entity_controller.rb sql injection

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/grit_entity_controll…

grit | Remote | Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
9.0 HIGH
CVE-2026-12187 — GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online …

gl-mt3000_firmware | Remote | Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
9.0 HIGH
CVE-2026-12186 — GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Ha…

gl-mt3000_firmware | Remote | Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.2 HIGH
CVE-2026-54413 — DriftRegion UDS Integer Underflow Out-of-Bounds Read

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated atta…

Remote | Memory Corruption
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.2 HIGH
CVE-2026-54412 — MQTT-C Heap Out-of-Bounds Read and Integer Underflow

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticate…

Remote | Memory Corruption
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
5.9 MEDIUM
CVE-2026-54411 — Linux-PAM pam_userdb Plaintext Password Recovery Timing Vulnerability

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or net…

linux-pam | Remote | Information Disclosure
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.6 HIGH
CVE-2026-54410 — nanoMODBUS TCP Server Off-by-One Buffer Overflow

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-control…

Remote | Memory Corruption
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
0.0 NA
CVE-2026-11527 — Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file ov…

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle open…

| Injection
Jun 14, 2026 Jun 15, 2026
Jun 14, 2026
Jun 15, 2026
9.8 CRITICAL
CVE-2026-11526 — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-ar…

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument wit…

Remote | Injection
Jun 14, 2026 Jun 15, 2026
Jun 14, 2026
Jun 15, 2026
0.0 NA
CVE-2025-15546 — Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use …

| Race Condition
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
6.8 MEDIUM
CVE-2026-54421 — OpenStack Ironic Information Disclosure

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentia…

ironic | Remote | Information Disclosure
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
Showing 20 of 6634 Results