Vulnerabilities

  

CVE-2026-78915 | Google Chrome up to 151.0.7922.173 race condition

A vulnerability was found in Google Chrome. It has been declared as critical. This affects an unknown function. Such manipulation

  

CVE-2026-77357 | mesop-dev mesop up to 1.3.2 Hot Reload counter infinite loop

A vulnerability was found in mesop-dev mesop up to 1.3.2. It has been rated as problematic. This impacts an unknown

  

CVE-2026-78912 | Google Chrome up to 151.0.7922.173

A vulnerability categorized as problematic has been discovered in Google Chrome. Affected is an unknown function. Executing a manipulation can

  

CVE-2026-77680 | Red Hat Enterprise Linux Range Coalescing soup-message-headers.c soup_message_headers_get_ranges_internal resource consumption (MR !550)

A vulnerability identified as problematic has been detected in Red Hat Enterprise Linux. Affected by this vulnerability is the function

  

CVE-2026-80101 | Red Hat Enterprise Linux XWD Image bytes-per-line out-of-bounds

A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux. Affected by this issue is some unknown

  

CVE-2026-78949 | Google Chrome up to 151.0.7922.173 CustomTabs cross-domain policy

A vulnerability marked as problematic has been reported in Google Chrome. This affects an unknown part of the component CustomTabs.

  

CVE-2026-78952 | Google Chrome up to 151.0.7922.173 Crashpad out-of-bounds write

A vulnerability described as critical has been identified in Google Chrome. This vulnerability affects unknown code of the component Crashpad.

  

CVE-2026-78955 | Google Chrome up to 151.0.7922.173 PerformanceAPIs cross-domain policy

A vulnerability classified as problematic has been found in Google Chrome. This issue affects some unknown processing of the component

  

CVE-2026-78958 | Google Chrome up to 151.0.7922.173 Skia uninitialized resource

A vulnerability classified as problematic was found in Google Chrome. Impacted is an unknown function of the component Skia. Executing

  

CVE-2026-78946 | Google Chrome up to 151.0.7922.173 improper authorization

A vulnerability, which was classified as critical, has been found in Google Chrome. The affected element is an unknown function.

  

CVE-2026-78947 | Google Chrome up to 151.0.7922.173 privileges management

A vulnerability, which was classified as critical, was found in Google Chrome. The impacted element is an unknown function. The

  

CVE-2026-78948 | Google Chrome up to 151.0.7922.173 WebGL buffer overflow

A vulnerability has been found in Google Chrome and classified as critical. This affects an unknown function of the component

  

CVE-2026-78950 | Google Chrome up to 151.0.7922.173 WebRTC integer overflow

A vulnerability was found in Google Chrome and classified as critical. This impacts an unknown function of the component WebRTC.

  

CVE-2026-78951 | Google Chrome up to 151.0.7922.173 ServiceWorker use after free

A vulnerability was found in Google Chrome. It has been classified as critical. Affected is an unknown function of the

  

CVE-2026-78953 | Google Chrome up to 151.0.7922.173 SiteIsolation privileges management

A vulnerability was found in Google Chrome. It has been declared as critical. Affected by this vulnerability is an unknown

  

CVE-2026-78954 | Google Chrome up to 151.0.7922.173 Extensions improper authorization

A vulnerability was found in Google Chrome. It has been rated as critical. Affected by this issue is some unknown

  

CVE-2026-78956 | Google Chrome up to 151.0.7922.173 V8 type confusion

A vulnerability categorized as critical has been discovered in Google Chrome. This affects an unknown part of the component V8.

  

CVE-2026-78959 | Google Chrome up to 151.0.7922.173 FileSystem access control

A vulnerability identified as critical has been detected in Google Chrome. This vulnerability affects unknown code of the component FileSystem.

  

CVE-2026-78960 | Google Chrome up to 151.0.7922.173 Extensions information disclosure

A vulnerability labeled as problematic has been found in Google Chrome. This issue affects some unknown processing of the component

  

CVE-2026-78961 | Google Chrome up to 151.0.7922.173 Core improper authorization

A vulnerability marked as critical has been reported in Google Chrome. Impacted is an unknown function of the component Core.

  

CVE-2026-75465 | Maccms 2026.1000.4055 api.php limit/offset access control

A vulnerability described as problematic has been identified in Maccms 2026.1000.4055. The affected element is an unknown function of the

  

CVE-2026-78957 | Google Chrome up to 151.0.7922.173 information disclosure

A vulnerability classified as problematic has been found in Google Chrome. The impacted element is an unknown function. The manipulation

  

CVE-2026-52489 | GPAC svgNameToImplementationName buffer overflow

A vulnerability classified as critical was found in GPAC. This affects the function svgNameToImplementationName. The manipulation results in buffer overflow.

  

CVE-2026-75421 | aria2 up to 1.37.0 IOFile::getLine stack-based overflow

A vulnerability, which was classified as problematic, has been found in aria2 up to 1.37.0. This impacts the function IOFile::getLine.

  

CVE-2026-48432 | Adobe Substance 3D Designer up to 16.0.4 buffer overflow

A vulnerability classified as critical was found in Adobe Substance 3D Designer up to 16.0.4. The affected element is an

  

CVE-2026-48433 | Adobe Substance 3D Designer up to 16.0.4 buffer overflow

A vulnerability, which was classified as problematic, has been found in Adobe Substance 3D Designer up to 16.0.4. The impacted

  

CVE-2026-71382 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 out-of-bounds write

A vulnerability, which was classified as problematic, was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. This affects an

  

CVE-2026-71441 | Adobe Illustrator out-of-bounds

A vulnerability has been found in Adobe Illustrator and classified as problematic. This impacts an unknown function. The manipulation leads

  

CVE-2026-71564 | Adobe Substance 3D Designer up to 16.0.4 out-of-bounds write

A vulnerability was found in Adobe Substance 3D Designer up to 16.0.4 and classified as critical. Affected is an unknown

  

CVE-2026-59983 | AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13 OpenEXRCore decoding.c unpack_sample_table out-of-bounds

A vulnerability was found in AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13. It has been classified as problematic. Affected by this vulnerability

  

CVE-2026-59984 | Academy Software Foundation OpenEXR up to 3.2.10/3.3.12/3.4.13 uncompress_b44_impl out-of-bounds write

A vulnerability was found in Academy Software Foundation OpenEXR up to 3.2.10/3.3.12/3.4.13. It has been declared as problematic. Affected by

  

CVE-2026-48429 | Adobe Substance 3D Designer up to 16.0.4 null pointer dereference

A vulnerability was found in Adobe Substance 3D Designer up to 16.0.4. It has been rated as problematic. This affects

  

CVE-2026-55620 | GOVCERT-LU eml_parser up to 3.0.1 Received Header Processing eml_parser/routing.py eml_parser.routing.noparenthesis redos

A vulnerability categorized as problematic has been discovered in GOVCERT-LU eml_parser up to 3.0.1. This vulnerability affects the function eml_parser.routing.noparenthesis

  

CVE-2026-55618 | eml_parser up to 3.0.1 eml_parser/parser.py clean_found_uri input validation

A vulnerability identified as problematic has been detected in eml_parser up to 3.0.1. This issue affects the function clean_found_uri of

  

CVE-2026-55619 | GOVCERT-LU eml_parser up to 3.0.1 Header Parser eml_parser/parser.py eml_parser.parser.HeaderParser.header_fetch_parse recursion

A vulnerability labeled as problematic has been found in GOVCERT-LU eml_parser up to 3.0.1. Impacted is the function eml_parser.parser.HeaderParser.header_fetch_parse of

  

CVE-2026-62986 | AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.13 PyPart PyPart::setDeepSliceData heap-based overflow

A vulnerability marked as problematic has been reported in AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.13. The affected element is the function

  

CVE-2026-79786 | Coroot up to 1.24.5 MCP OAuth Dynamic Client Registration Endpoint redirect

A vulnerability described as problematic has been identified in Coroot up to 1.24.5. The impacted element is an unknown function

  

CVE-2026-80049 | Airbyte Platform up to 2.0.0 Authorization Server AuthenticationHeaderResolver.resolveWorkspace permission

A vulnerability classified as critical has been found in Airbyte Platform up to 2.0.0. This affects the function AuthenticationHeaderResolver.resolveWorkspace of

  

CVE-2026-59985 | AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13 OpenEXRCore decoding.c unpack_32bit out-of-bounds

A vulnerability classified as problematic was found in AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13. This impacts the function unpack_32bit of the

  

CVE-2026-61555 | AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13 MultiView Header Processing GetChannelsInMultiPartFile out-of-bounds

A vulnerability, which was classified as problematic, has been found in AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13. Affected is the function

  

CVE-2026-79787 | Alluxio up to 2.9.5 S3 REST proxy improper authentication

A vulnerability, which was classified as very critical, was found in Alluxio up to 2.9.5. Affected by this vulnerability is

  

CVE-2026-80050 | continew-org Admin up to 4.1.0 unrestricted upload

A vulnerability has been found in continew-org Admin up to 4.1.0 and classified as critical. Affected by this issue is

  

CVE-2026-55663 | versatica mediasoup up to 0.22.4/3.20.5 SCTP Stack StateCookie.hpp IsMediasoupStateCookie improper authentication

A vulnerability was found in versatica mediasoup up to 0.22.4/3.20.5 and classified as critical. This affects the function StateCookie::IsMediasoupStateCookie of

  

CVE-2026-79788 | Dradis up to 5.2.x ProvidersController/AgentsController admin_required server-side request forgery

A vulnerability was found in Dradis up to 5.2.x. It has been classified as critical. This vulnerability affects the function

  

CVE-2026-55609 | ruvnet sublinear-time-solver up to 1.5.x Export State Tool server.js export_state filepath path traversal

A vulnerability was found in ruvnet sublinear-time-solver up to 1.5.x. It has been declared as problematic. This issue affects the

  

CVE-2026-78379 | Amazon Strands Agents Tools up to 0.8.4 Python REPL Tool non_interactive_mode neutralization

A vulnerability was found in Amazon Strands Agents Tools up to 0.8.4. It has been rated as critical. Impacted is

  

CVE-2026-45018 | Chainlit up to 2.11.x MCP Endpoint backend/chainlit/mcp.py validate_mcp_command fullCommand os command injection

A vulnerability categorized as critical has been discovered in Chainlit up to 2.11.x. The affected element is the function validate_mcp_command

  

CVE-2026-65979 | AcademySoftwareFoundation OpenEXR up to 3.4.12 HTJ2K decoder input validation

A vulnerability identified as critical has been detected in AcademySoftwareFoundation OpenEXR up to 3.4.12. The impacted element is an unknown

  

CVE-2026-68513 | AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.13 PyOpenEXR channelNameToRGBA heap-based overflow

A vulnerability labeled as problematic has been found in AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.13. This affects the function channelNameToRGBA of

  

CVE-2026-59184 | Academy Software Foundation OpenEXR up to 3.2.10/3.3.12/3.4.13 FlatHalfChannel FlatHalfChannel::row dataWindow.min use after free

A vulnerability was found in Academy Software Foundation OpenEXR up to 3.2.10/3.3.12/3.4.13. It has been declared as problematic. Affected by

  

CVE-2026-59186 | AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13 TiledRgbaInputFile out-of-bounds write

A vulnerability was found in AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13. It has been rated as problematic. Affected by this issue

  

CVE-2026-75497 | Webkul QloApps CustomerMessage.php bo_query sql injection (123c97c)

A vulnerability categorized as problematic has been discovered in Webkul QloApps. This affects an unknown part of the file CustomerMessage.php.

  

CVE-2026-75498 | Webkul QloApps Address.php bo_query sql injection (123c97c)

A vulnerability identified as problematic has been detected in Webkul QloApps. This vulnerability affects unknown code of the file Address.php.

  

CVE-2026-16234 | NI LabVIEW up to 26.3.0 memory corruption

A vulnerability labeled as problematic has been found in NI LabVIEW up to 22.x/23.3.9/24.3.6/25.3.4/26.3.0. This issue affects some unknown processing.

  

CVE-2026-64201 | NI LabVIEW up to 26.3.0 memory corruption

A vulnerability marked as problematic has been reported in NI LabVIEW up to 22.x/23.3.9/24.3.6/25.3.4/26.3.0. Impacted is an unknown function. The

  

CVE-2026-64202 | NI LabVIEW up to 26.3.0 memory corruption

A vulnerability described as critical has been identified in NI LabVIEW up to 22.x/23.3.9/24.3.6/25.3.4/26.3.0. The affected element is an unknown

  

CVE-2026-64203 | NI LabVIEW up to 26.3.0 memory corruption

A vulnerability classified as problematic has been found in NI LabVIEW up to 22.x/23.3.9/24.3.6/25.3.4/26.3.0. The impacted element is an unknown

  

CVE-2026-64204 | NI LabVIEW up to 26.3.0 memory corruption

A vulnerability classified as critical was found in NI LabVIEW up to 22.x/23.3.9/24.3.6/25.3.4/26.3.0. This affects an unknown function. Such manipulation

  

CVE-2026-75496 | Webkul QloApps unrestricted upload (153ec1c)

A vulnerability, which was classified as problematic, has been found in Webkul QloApps. This impacts an unknown function. Performing a

  

CVE-2026-59189 | AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.12 TypedDeepImageChannel row out-of-bounds

A vulnerability, which was classified as critical, was found in AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.12. Affected is the function TypedDeepImageChannel::row

  

CVE-2026-59187 | AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.13 DeepSlice out-of-bounds write

A vulnerability has been found in AcademySoftwareFoundation OpenEXR up to 3.3.12/3.4.13 and classified as problematic. Affected by this vulnerability is

  

CVE-2026-79992 | Red Hat Enterprise Linux TRAMP os command injection

A vulnerability was found in Red Hat Enterprise Linux and classified as very critical. Affected by this issue is some

  

CVE-2026-76195 | Adobe Campaign Classic os command injection

A vulnerability was found in Adobe Campaign Classic. It has been classified as critical. This affects an unknown part. This

  

CVE-2026-76197 | Adobe Campaign Classic os command injection

A vulnerability was found in Adobe Campaign Classic. It has been declared as very critical. This vulnerability affects unknown code.

  

CVE-2026-26211 | Creativeitem Ekushey Project Manager CRM up to 5.0 cross site scripting

A vulnerability was found in Creativeitem Ekushey Project Manager CRM up to 5.0. It has been rated as problematic. This

  

CVE-2026-71360 | Adobe C2PA Tool/Content Credentials Rust SDK resource consumption

A vulnerability categorized as problematic has been discovered in Adobe C2PA Tool and Content Credentials Rust SDK. Impacted is an

  

CVE-2026-76193 | Adobe Campaign Classic server-side request forgery

A vulnerability identified as critical has been detected in Adobe Campaign Classic. The affected element is an unknown function. The

  

CVE-2026-55419 | pollen-robotics reachy_mini up to 1.8.1 media.py upload_sound unrestricted upload

A vulnerability labeled as critical has been found in pollen-robotics reachy_mini up to 1.8.1. The impacted element is the function

  

CVE-2026-71442 | Adobe C2PA Tool/Content Credentials integer underflow

A vulnerability marked as problematic has been reported in Adobe C2PA Tool and Content Credentials. This affects an unknown function.

  

CVE-2026-71443 | Adobe C2PA Tool/Content Credentials Rust SDK input validation

A vulnerability described as problematic has been identified in Adobe C2PA Tool and Content Credentials Rust SDK. This impacts an

  

CVE-2026-71444 | Adobe C2PA Tool/Content Credentials SDK integer underflow

A vulnerability classified as problematic has been found in Adobe C2PA Tool and Content Credentials SDK. Affected is an unknown

  

CVE-2026-76189 | Adobe C2PA Tool/Content Credentials Rust SDK integer underflow

A vulnerability classified as problematic was found in Adobe C2PA Tool and Content Credentials Rust SDK. Affected by this vulnerability

  

CVE-2026-76198 | Adobe Content Credentials Rust SDK/C2PA Tool input validation

A vulnerability, which was classified as problematic, has been found in Adobe Content Credentials Rust SDK and C2PA Tool. Affected

  

CVE-2026-71399 | Adobe XD up to 60 buffer overflow

A vulnerability, which was classified as critical, was found in Adobe XD up to 60. This affects an unknown part.

  

CVE-2026-59982 | AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13 TypedDeepImageChannel row out-of-bounds

A vulnerability has been found in AcademySoftwareFoundation OpenEXR up to 3.2.10/3.3.12/3.4.13 and classified as critical. This vulnerability affects the function

  

CVE-2026-75749 | Adobe Substance 3D Painter up to 12.1.2 out-of-bounds write

A vulnerability was found in Adobe Substance 3D Painter up to 12.1.2 and classified as critical. This issue affects some

  

CVE-2026-75750 | Adobe Substance 3D Painter up to 12.1.2 buffer overflow

A vulnerability was found in Adobe Substance 3D Painter up to 12.1.2. It has been classified as critical. Impacted is

  

CVE-2026-75752 | Adobe Substance 3D Painter up to 12.1.2 out-of-bounds

A vulnerability was found in Adobe Substance 3D Painter up to 12.1.2. It has been declared as problematic. The affected

  

CVE-2026-75766 | Adobe Substance 3D Painter up to 12.1.2 buffer overflow

A vulnerability was found in Adobe Substance 3D Painter up to 12.1.2. It has been rated as problematic. The impacted

  

CVE-2026-75767 | Adobe Substance 3D Painter up to 12.1.2 buffer overflow

A vulnerability categorized as critical has been discovered in Adobe Substance 3D Painter up to 12.1.2. This affects an unknown

  

CVE-2026-75768 | Adobe Substance 3D Painter up to 12.1.2 untrusted search path

A vulnerability identified as critical has been detected in Adobe Substance 3D Painter up to 12.1.2. This impacts an unknown

  

CVE-2026-75769 | Adobe Substance 3D Painter up to 12.1.2 buffer overflow

A vulnerability labeled as problematic has been found in Adobe Substance 3D Painter up to 12.1.2. Affected is an unknown

  

CVE-2026-75770 | Adobe Substance 3D Painter up to 12.1.2 out-of-bounds write

A vulnerability marked as critical has been reported in Adobe Substance 3D Painter up to 12.1.2. Affected by this vulnerability

  

CVE-2026-80051 | graphql-go up to 0.8.1 Scalar Coercion scalars.go coerceString/coerceBool stack-based overflow

A vulnerability described as problematic has been identified in graphql-go up to 0.8.1. Affected by this issue is the function

  

CVE-2026-48417 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 stack-based overflow

A vulnerability classified as critical has been found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. This affects an unknown

  

CVE-2026-48418 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 out-of-bounds write

A vulnerability classified as problematic was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. This vulnerability affects unknown code.

  

CVE-2026-48419 | Adobe Substance 3D Sampler up to 6.0.2 out-of-bounds write

A vulnerability, which was classified as problematic, has been found in Adobe Substance 3D Sampler up to 6.0.2. This issue

  

CVE-2026-48420 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 out-of-bounds write

A vulnerability, which was classified as critical, was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. Impacted is an

  

CVE-2026-48421 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 out-of-bounds write

A vulnerability has been found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2 and classified as critical. The affected element

  

CVE-2026-48422 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 buffer overflow

A vulnerability was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2 and classified as problematic. The impacted element is

  

CVE-2026-48423 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 buffer overflow

A vulnerability was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. It has been classified as critical. This affects

  

CVE-2026-48424 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 buffer overflow

A vulnerability was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. It has been declared as critical. This impacts

  

CVE-2026-48425 | Adobe Substance 3D Sampler up to 6.0.1/6.0.2 buffer overflow

A vulnerability was found in Adobe Substance 3D Sampler up to 6.0.1/6.0.2. It has been rated as critical. Affected is

  

CVE-2026-55637 | GeiserX genieacs-mcp up to 0.3.1 Streamable HTTP transport cmd/server/main.go Start dns rebinding

A vulnerability categorized as critical has been discovered in GeiserX genieacs-mcp up to 0.3.1. Affected by this vulnerability is the

  

CVE-2026-48426 | Adobe Substance 3D Designer up to 16.0.4 out-of-bounds write

A vulnerability identified as problematic has been detected in Adobe Substance 3D Designer up to 16.0.4. Affected by this issue

  

CVE-2026-48427 | Adobe Substance 3D Designer up to 16.0.4 out-of-bounds write

A vulnerability labeled as critical has been found in Adobe Substance 3D Designer up to 16.0.4. This affects an unknown

  

CVE-2026-48428 | Adobe Substance 3D Designer up to 16.0.4 buffer overflow

A vulnerability marked as critical has been reported in Adobe Substance 3D Designer up to 16.0.4. This vulnerability affects unknown

  

CVE-2026-48430 | Adobe Substance 3D Designer up to 16.0.4 buffer overflow

A vulnerability described as problematic has been identified in Adobe Substance 3D Designer up to 16.0.4. This issue affects some

  

CVE-2026-48431 | Adobe Substance 3D Designer up to 16.0.4 buffer overflow

A vulnerability classified as critical has been found in Adobe Substance 3D Designer up to 16.0.4. Impacted is an unknown

  

CVE-2026-55537 | MervinPraison PraisonAI up to 4.6.57 Webhook Validation JobSubmitRequest.validate_webhook_url server-side request forgery

A vulnerability has been found in MervinPraison PraisonAI up to 4.6.57 and classified as critical. This issue affects the function