Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-52722

Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor payload handling_CVE-2026-52722

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow sign...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.8 CVE-2026-52720

Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb_CVE-2026-52720

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 7.1 CVE-2026-52719

Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoder_CVE-2026-52719

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value f...

Red Hat Red Hat Enterprise Linux 10 CVE
HIGH 8.6 CVE-2026-49954

Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory_CVE-2026-49954

Discuz! X5.0 releases 20260320 through 20260501 contain a local file inclusion vulnerability that allows authenticated administrators to execute ar...

Discuz! Discuz! X5.0 20260320 CVE
HIGH 8.6 CVE-2026-47835

Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores_CVE-2026-47835

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire ...

Spring Spring AI 1.0.0 CVE
HIGH 8.6 CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle_CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_...

SHLOMIF Config::IniFiles CVE
HIGH 7.5 CVE-2026-41708

Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability_CVE-2026-41708

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The applic...

Spring Spring Cloud Sleuth 3.1.0 CVE
HIGH 8.3 B8597AF3-5382-

Exploit for CVE-2025-2783_B8597AF3-5382-5D92-B7C2-B9350D29B3DD

Chromium CVE-2025-2783: Sandbox Escape & Full-Chain RCE Exploit This repository contains a full-chain exploit implementation for CVE-2025-2783. The...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 CVE-2026-47777

Mastodon has a consent-check bypass in its remote Collections_CVE-2026-47777

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote account...

mastodon mastodon >= nightly.2026-03-10, < 4.6.0-beta.1 CVE
HIGH 8.8 THN:DED9C232B49...

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers_THN:DED9C232B49BBF1CB0977760C793F104

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiH9LcMRhk5Li59rG05yXoOOofNzGpeG1MMSKQqhFCGW_28n0SjLKd9D4MC68N7jPP6dF2h2l8gW1OE7Y7ak...

N/A N/A THN