Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2025-55649

CVE-2025-55649_CVE-2025-55649

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Se...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55648

CVE-2025-55648_CVE-2025-55648

A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55647

CVE-2025-55647_CVE-2025-55647

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (D...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55645

CVE-2025-55645_CVE-2025-55645

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55644

CVE-2025-55644_CVE-2025-55644

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Serv...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55643

CVE-2025-55643_CVE-2025-55643

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Ser...

n/a n/a n/a CVE
MEDIUM 6.5 CVE-2025-55642

CVE-2025-55642_CVE-2025-55642

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55641

CVE-2025-55641_CVE-2025-55641

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial ...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2026-9691

WordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.1 - PHP Object Injection vulnerability_CVE-2026-9691

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms

CRM Perks Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms 1.1.1 CVE
CRITICAL 9.6 CVE-2026-52703

WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability_CVE-2026-52703

Unauthenticated Path Traversal in FastDup

Ninja Team FastDup n/a CVE