Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 23C71CB7-8C77-

Exploit for Uncontrolled Resource Consumption in Microsoft_23C71CB7-8C77-57E5-804D-D2FD022715BE

CVE-2026-49160-HTTP.sys HTTP.sys Denial of Service Vulnerability PoC...

N/A N/A GITHUBEXPLOIT
HIGH 7.6 CVE-2026-53705

Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder via integer overflow_CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 7.1 CVE-2026-53704

Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser_CVE-2026-53704

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted ...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 7.1 CVE-2026-53703

Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser_CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (m...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 7.1 CVE-2026-52722

Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor payload handling_CVE-2026-52722

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow sign...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.8 CVE-2026-52720

Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb_CVE-2026-52720

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 7.1 CVE-2026-52719

Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoder_CVE-2026-52719

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value f...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2026-49954

Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory_CVE-2026-49954

Discuz! X5.0 releases 20260320 through 20260501 contain a local file inclusion vulnerability that allows authenticated administrators to execute ar...

Discuz! Discuz! X5.0 20260320 CVE
HIGH 8.6 CVE-2026-47835

Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores_CVE-2026-47835

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire ...

Spring Spring AI 1.0.0 CVE
HIGH 8.6 CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle_CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_...

SHLOMIF Config::IniFiles CVE