Common Vulnerabilities and Exposures (CVE)

CVE-2026-56412

Jun 21, 2026 15:58:59 UTC

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issu...

CVE-2026-56411

Jun 21, 2026 15:56:42 UTC

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVE-2026-56410

Jun 21, 2026 15:55:00 UTC

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVE-2026-56409

Jun 21, 2026 15:52:59 UTC

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVE-2026-56408

Jun 21, 2026 15:51:11 UTC

libexpat before 2.8.2 has an integer overflow in copyString.

CVE-2026-56407

Jun 21, 2026 15:49:35 UTC

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVE-2026-56406

Jun 21, 2026 15:48:21 UTC

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

CVE-2026-56405

Jun 21, 2026 15:47:13 UTC

libexpat before 2.8.2 has an integer overflow in getAttributeId.

CVE-2026-56404

Jun 21, 2026 15:45:55 UTC

libexpat before 2.8.2 has an integer overflow in addBinding.

CVE-2026-56403

Jun 21, 2026 15:43:55 UTC

libexpat before 2.8.2 has an integer overflow in storeAtts.

CVE-2026-11526

Jun 21, 2026 13:34:16 UTC

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that...

CVE-2026-56397

Jun 21, 2026 13:27:04 UTC

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsi...

CVE-2026-56396

Jun 21, 2026 13:27:03 UTC

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_su...

CVE-2026-56395

Jun 21, 2026 13:27:03 UTC

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsi...

CVE-2026-56394

Jun 21, 2026 13:27:02 UTC

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing tr...