Common Vulnerabilities and Exposures (CVE)

CVE-2023-34854

Sep 14, 2026 05:06:49 UTC

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

CVE-2026-90684

Sep 14, 2026 05:00:12 UTC

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion....

CVE-2023-32803

Sep 14, 2026 05:00:02 UTC

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491...

CVE-2023-32778

Sep 14, 2026 04:52:19 UTC

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

CVE-2026-90683

Sep 14, 2026 04:45:12 UTC

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally i...

CVE-2023-29377

Sep 14, 2026 04:43:54 UTC

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA obj...

CVE-2023-28148

Sep 14, 2026 04:34:03 UTC

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

CVE-2026-90682

Sep 14, 2026 04:30:16 UTC

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG lea...

CVE-2026-10420

Sep 14, 2026 04:29:23 UTC

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

CVE-2023-24291

Sep 14, 2026 04:24:13 UTC

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

CVE-2023-24288

Sep 14, 2026 04:21:03 UTC

An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.

CVE-2023-24287

Sep 14, 2026 04:17:29 UTC

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

CVE-2026-90681

Sep 14, 2026 04:15:11 UTC

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit...

CVE-2023-24286

Sep 14, 2026 04:14:23 UTC

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

CVE-2023-24285

Sep 14, 2026 04:10:33 UTC

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.