Common Vulnerabilities and Exposures (CVE)

CVE-2023-46273

Sep 14, 2026 05:54:24 UTC

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

CVE-2026-16726

Sep 14, 2026 05:53:54 UTC

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

CVE-2023-46035

Sep 14, 2026 05:49:09 UTC

The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.

CVE-2026-90687

Sep 14, 2026 05:45:09 UTC

A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possibl...

CVE-2023-45858

Sep 14, 2026 05:38:11 UTC

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

CVE-2023-45023

Sep 14, 2026 05:34:00 UTC

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

CVE-2026-90686

Sep 14, 2026 05:30:13 UTC

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. ...

CVE-2026-85150

Sep 14, 2026 05:29:18 UTC

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around...

CVE-2023-40772

Sep 14, 2026 05:29:11 UTC

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

CVE-2026-18369

Sep 14, 2026 05:28:08 UTC

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME ...

CVE-2023-37366

Sep 14, 2026 05:23:56 UTC

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos ...

CVE-2026-16313

Sep 14, 2026 05:21:41 UTC

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied...

CVE-2023-37253

Sep 14, 2026 05:16:42 UTC

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

CVE-2026-90685

Sep 14, 2026 05:15:08 UTC

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required...

CVE-2023-37252

Sep 14, 2026 05:12:30 UTC

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.