Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-60474

CVE-2025-60474_CVE-2025-60474

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Den...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-60467

CVE-2025-60467_CVE-2025-60467

A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attac...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-60473

CVE-2025-60473_CVE-2025-60473

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attac...

n/a n/a n/a CVE
MEDIUM 5 CVE-2025-60466

CVE-2025-60466_CVE-2025-60466

A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cau...

n/a n/a n/a CVE
HIGH 7.5 CVE-2026-9702

InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking_CVE-2026-9702

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce o...

Unknown InPost PL CVE
HIGH 8.8 CVE-2026-5305

Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Stored XSS_CVE-2026-5305

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email repla...

Unknown Email Address Encoder CVE
MEDIUM 6.5 CVE-2026-10824

Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion_CVE-2026-10824

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthent...

Unknown Masteriyo LMS CVE
LOW 3.7 CVE-2026-42004

EDNS options smuggling_CVE-2026-42004

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when ...

PowerDNS DNSdist 1.9.0 CVE
MEDIUM 5.3 CVE-2026-40211

Denial of service via crafted DoH3 queries_CVE-2026-40211

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer wil...

PowerDNS DNSdist 1.9.0 CVE
MEDIUM 4.8 CVE-2026-40210

Out-of-bounds read in SetMacAddrAction_CVE-2026-40210

An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a cr...

PowerDNS DNSdist 1.9.0 CVE