Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-52721

Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapparse ipv4/tcp header parsing_CVE-2026-52721

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer bou...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.8 CVE-2026-52720

Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb_CVE-2026-52720

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 7.1 CVE-2026-52719

Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoder_CVE-2026-52719

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value f...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 6.5 CVE-2026-52718

Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusion_CVE-2026-52718

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function p...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2026-49954

Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory_CVE-2026-49954

Discuz! X5.0 releases 20260320 through 20260501 contain a local file inclusion vulnerability that allows authenticated administrators to execute ar...

Discuz! Discuz! X5.0 20260320 CVE
MEDIUM 6.9 CVE-2026-49953

Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set_CVE-2026-49953

Discuz! X5.0 releases 20260320 through 20260501 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat chal...

Discuz! Discuz! X5.0 20260320 CVE
CRITICAL 9.3 CVE-2026-49952

Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle_CVE-2026-49952

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gai...

Discuz! Discuz! X5.0 20260320 CVE
CRITICAL 9.8 CVE-2026-48114

Metacat has an unauthenticated SQL injection vulnerability_CVE-2026-48114

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthentica...

NCEAS metacat >= 2.0.0, < 3.0.0 CVE
HIGH 8.6 CVE-2026-47835

Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores_CVE-2026-47835

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire ...

Spring Spring AI 1.0.0 CVE
HIGH 8.6 CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle_CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_...

SHLOMIF Config::IniFiles CVE