Common Vulnerabilities and Exposures (CVE)

CVE-2026-65706

Jul 24, 2026 03:56:31 UTC

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame(...

CVE-2026-65705

Jul 24, 2026 03:56:30 UTC

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization dis...

CVE-2026-65704

Jul 24, 2026 03:56:30 UTC

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packe...

CVE-2026-65703

Jul 24, 2026 03:56:29 UTC

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames....

CVE-2026-44359

Jul 24, 2026 03:56:28 UTC

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code an...

CVE-2026-47668

Jul 24, 2026 03:56:27 UTC

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. Th...

CVE-2026-6516

Jul 24, 2026 03:56:26 UTC

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

CVE-2026-64809

Jul 24, 2026 03:56:25 UTC

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CVE-2026-64808

Jul 24, 2026 03:56:25 UTC

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

CVE-2026-64807

Jul 24, 2026 03:56:24 UTC

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVE-2026-64806

Jul 24, 2026 03:56:23 UTC

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CVE-2026-64805

Jul 24, 2026 03:56:22 UTC

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CVE-2026-64804

Jul 24, 2026 03:56:21 UTC

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

CVE-2026-65908

Jul 24, 2026 03:56:20 UTC

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CVE-2026-65907

Jul 24, 2026 03:56:19 UTC

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible