Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-12921

Use after free in AzeoTech DAQFactory_CVE-2026-12921

In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files w...

AzeoTech DAQFactory CVE
HIGH 8.4 CVE-2026-12897

Out-of-bounds read in Horner Automation Cscape_CVE-2026-12897

Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exp...

Horner Automation Cscape CVE
HIGH 7.5 CVE-2025-61028

CVE-2025-61028_CVE-2025-61028

An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL ...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-60468

CVE-2025-60468_CVE-2025-60468

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a d...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-60474

CVE-2025-60474_CVE-2025-60474

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Den...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-60467

CVE-2025-60467_CVE-2025-60467

A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attac...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-60473

CVE-2025-60473_CVE-2025-60473

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attac...

n/a n/a n/a CVE
MEDIUM 5 CVE-2025-60466

CVE-2025-60466_CVE-2025-60466

A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cau...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-9702

InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking_CVE-2026-9702

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce o...

Unknown InPost PL CVE
HIGH 8.8 CVE-2026-5305

Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Stored XSS_CVE-2026-5305

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email repla...

Unknown Email Address Encoder CVE