Common Vulnerabilities and Exposures (CVE)

CVE-2026-108539

Oct 11, 2026 05:00:12 UTC

A vulnerability was detected in GPAC up to 26.07.0. This affects the function gf_fq_pop of the file filter_core/filter_queue.c of the component MP4Box. Performing a manipulation results in use after free. The attack may be initiated remotel...

CVE-2026-108538

Oct 11, 2026 04:45:11 UTC

A security vulnerability has been detected in GPAC up to 26.07.0. The impacted element is the function gf_mx_v of the file utils/os_thread.c of the component MP4Box. Such manipulation leads to use after free. The attack can be launched remo...

CVE-2026-33818

Oct 11, 2026 04:22:15 UTC

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

CVE-2026-42504

Oct 11, 2026 04:22:13 UTC

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

CVE-2024-1525

Oct 11, 2026 04:18:10 UTC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP u...

CVE-2023-5963

Oct 11, 2026 04:17:03 UTC

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too ma...

CVE-2023-5831

Oct 11, 2026 04:16:58 UTC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_ou...

CVE-2026-108523

Oct 11, 2026 04:15:16 UTC

A vulnerability was determined in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repo_url c...

CVE-2026-108522

Oct 11, 2026 04:00:17 UTC

A vulnerability was found in Studio-Saelix Sencho up to 0.94.1. This affects an unknown part of the file /api/auth/login of the component Login Endpoint. Performing a manipulation of the argument X-Forwarded-For results in improper authenti...

CVE-2026-108521

Oct 11, 2026 02:45:12 UTC

A vulnerability has been found in Studio-Saelix Sencho up to 0.97.1. Affected by this issue is the function isValidRemoteUrl of the file backend/src/utils/validation.ts of the component Add Remote Node API Endpoint. Such manipulation leads ...

CVE-2026-108696

Oct 11, 2026 01:35:45 UTC

CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderC...

CVE-2026-108695

Oct 11, 2026 01:35:44 UTC

MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST...

CVE-2026-108694

Oct 11, 2026 01:35:44 UTC

ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText d...

CVE-2026-108693

Oct 11, 2026 01:35:43 UTC

ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by bare name when Ghostscript is unregistered. Attackers can plant a malicious gswin64...

CVE-2026-108708

Oct 11, 2026 01:12:32 UTC

Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged...