Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2025-55645

CVE-2025-55645_CVE-2025-55645

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55644

CVE-2025-55644_CVE-2025-55644

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Serv...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55643

CVE-2025-55643_CVE-2025-55643

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Ser...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2025-55642

CVE-2025-55642_CVE-2025-55642

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55641

CVE-2025-55641_CVE-2025-55641

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial ...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-49775

WordPress Welcart e-Commerce plugin <= 2.11.28 - Broken Access Control vulnerability_CVE-2026-49775

Unauthenticated Broken Access Control in Welcart e-Commerce

info@welcart Welcart e-Commerce n/a CVE
MEDIUM 6.5 CVE-2026-49773

WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Scripting (XSS) vulnerability_CVE-2026-49773

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

FolioVision FV Flowplayer Video Player n/a CVE
MEDIUM 4.7 CVE-2026-49043

WordPress WP Migrate Lite plugin <= 2.7.8 - Cross Site Request Forgery (CSRF) vulnerability_CVE-2026-49043

Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite

WP Engine WP Migrate Lite n/a CVE
MEDIUM 6.5 CVE-2026-48965

WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability_CVE-2026-48965

Subscriber Sensitive Data Exposure in XCloner

watchful XCloner n/a CVE
MEDIUM 6.5 CVE-2026-48887

WordPress JS Help Desk plugin <= 3.0.9 - Broken Access Control vulnerability_CVE-2026-48887

Unauthenticated Broken Access Control in JS Help Desk

Ahmad JS Help Desk n/a CVE