Common Vulnerabilities and Exposures (CVE)

CVE-2026-12811

Jun 21, 2026 22:00:10 UTC

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the...

CVE-2026-12810

Jun 21, 2026 21:45:07 UTC

A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in co...

CVE-2026-12809

Jun 21, 2026 21:30:08 UTC

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command i...

CVE-2026-12808

Jun 21, 2026 20:45:08 UTC

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection. The attac...

CVE-2026-12807

Jun 21, 2026 19:45:07 UTC

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in comm...

CVE-2026-12806

Jun 21, 2026 19:30:08 UTC

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to ...

CVE-2026-12805

Jun 21, 2026 19:15:07 UTC

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed fro...

CVE-2026-12804

Jun 21, 2026 18:30:07 UTC

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of t...

CVE-2026-56412

Jun 21, 2026 15:58:59 UTC

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issu...

CVE-2026-56411

Jun 21, 2026 15:56:42 UTC

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVE-2026-56410

Jun 21, 2026 15:55:00 UTC

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVE-2026-56409

Jun 21, 2026 15:52:59 UTC

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVE-2026-56408

Jun 21, 2026 15:51:11 UTC

libexpat before 2.8.2 has an integer overflow in copyString.

CVE-2026-56407

Jun 21, 2026 15:49:35 UTC

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVE-2026-56406

Jun 21, 2026 15:48:21 UTC

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.