Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2025-60468

CVE-2025-60468_CVE-2025-60468

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a d...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-60473

CVE-2025-60473_CVE-2025-60473

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attac...

n/a n/a n/a CVE
MEDIUM 5 CVE-2025-60466

CVE-2025-60466_CVE-2025-60466

A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cau...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2026-10824

Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion_CVE-2026-10824

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthent...

Unknown Masteriyo LMS CVE
MEDIUM 5.3 CVE-2026-40211

Denial of service via crafted DoH3 queries_CVE-2026-40211

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer wil...

PowerDNS DNSdist 1.9.0 CVE
MEDIUM 4.8 CVE-2026-40210

Out-of-bounds read in SetMacAddrAction_CVE-2026-40210

An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a cr...

PowerDNS DNSdist 1.9.0 CVE
MEDIUM 5.3 CVE-2026-40209

Denial of service via IXFR queries_CVE-2026-40209

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by...

PowerDNS DNSdist 1.9.0 CVE
MEDIUM 6.5 CVE-2026-57619

WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerability_CVE-2026-57619

Contributor Sensitive Data Exposure in Elementor Website Builder

Elementor Elementor Website Builder n/a CVE
MEDIUM 6.5 CVE-2026-57429

WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability_CVE-2026-57429

Contributor Broken Access Control in Slim SEO

eLightUp Slim SEO n/a CVE
MEDIUM 6.5 CVE-2026-56050

WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerability_CVE-2026-56050

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. T...

Themeisle PPOM for WooCommerce n/a CVE