Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-47373

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.

PUBLISHED
Vendor
RRWO
Product
Crypt::SaltedHash
Provider severity
HIGH
Conflicts
0

CVE-2026-47372

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

PUBLISHED
Vendor
RRWO
Product
Crypt::SaltedHash
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
EFG, UCK-Enterprise, UDM-Beast, UNVR, UNAS-Pro-8, UNAS-2, UNVR-Pro, UDM, UCG-Ultra, UniFi OS Server, UNVR-G2, UNAS-Pro, UCG-Fiber, UCKP, ENVR, ENVR-Core, UNAS-Pro-4, Express, UDW, UDR, UDM-Pro-Max, UCG-Industrial, UDR-5G, Express 7, UCK, UDR7, UCG-Max, UDM-Pro, UDM-SE, UNVR-Instant, UNVR-G2-Pro, UNAS-4
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4737

Use After Free vulnerability in No-Chicken Echo-Mate (‎SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerability is associated with program files rmap.C‎. This issue affects Echo-Mate: before V250329.

PUBLISHED
Vendor
No-Chicken
Product
Echo-Mate
Provider severity
HIGH
Conflicts
0

CVE-2026-47369

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
EFG, UCG-Ultra, Express 7, UNVR-G2-Pro, UNAS-Pro, UNAS-2, UNAS-Pro-8, Express, UNVR-G2, ENVR-Core, UCK-Enterprise, UCG-Max, UDM-Pro, UDM-Beast, UCKP, UDM, UDR, UniFi OS Server, UDM-SE, UNVR-Instant, UCG-Industrial, UNVR-Pro, ENVR, UCG-Fiber, UNAS-4, UDW, UDM-Pro-Max, UDR7, UNVR, UCK, UDR-5G, UNAS-Pro-4
Provider severity
CRITICAL
Conflicts
1

CVE-2026-47368

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
Express, UNVR-G2-Pro, UNVR-G2, EFG, UDM-SE, UCK-Enterprise, UniFi OS Server, Express 7, UDM-Beast, UCG-Industrial, ENVR-Core, UDM-Pro-Max, UNAS-Pro-8, UNVR, UNAS-Pro, UCKP, UNVR-Instant, UDR, UNVR-Pro, UDW, UCG-Max, UDM-Pro, UCG-Fiber, UDR-5G, UDR7, UCK, ENVR, UNAS-Pro-4, UNAS-2, UDM, UNAS-4, UCG-Ultra
Provider severity
HIGH
Conflicts
1

CVE-2026-47367

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UID Enterprise Agent
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47366

Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.

PUBLISHED
Vendor
phpBB
Product
phpBB
Provider severity
HIGH
Conflicts
0

CVE-2026-47365

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

PUBLISHED
Vendor
WebPros
Product
WordPress-Toolkit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4736

Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfilter modules). This vulnerability is associated with program files nf_tables.H‎, nft_byteorder.C‎, nft_meta.C‎. This issue affects Echo-Mate: before V250329.

PUBLISHED
Vendor
No-Chicken
Product
Echo-Mate
Provider severity
HIGH
Conflicts
0

CVE-2026-47358

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticated remote attacker can upload an ARM template containing a templateLink.uri or parametersLink.uri fiel

PUBLISHED
Vendor
tenable
Product
Terrascan
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-47357

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's HttpGetter supports the X-Terraform-Get response heade

PUBLISHED
Vendor
tenable
Product
Terrascan
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-47356

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request to the attacker-controlled URL containing the full scan results as a JSON body, with the attacker-sup

PUBLISHED
Vendor
tenable
Product
Terrascan
Provider severity
HIGH
Conflicts
1

CVE-2026-47352

Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47351

Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-47350

Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4735

Deserialization of Untrusted Data vulnerability in DTStack chunjun (‎chunjun-core/src/main/java/com/dtstack/chunjun/util modules). This vulnerability is associated with program files GsonUtil.Java. This issue affects chunjun: before 1.16.1.

PUBLISHED
Vendor
DTStack
Product
chunjun
Provider severity
HIGH
Conflicts
0

CVE-2026-47349

Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47348

Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47347

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47346

Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
HIGH
Conflicts
1

CVE-2026-47345

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

PUBLISHED
Vendor
TYPO3
Product
HTML Sanitizer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47344

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

PUBLISHED
Vendor
TYPO3
Product
HTML Sanitizer
Provider severity
LOW
Conflicts
1

CVE-2026-47343

Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
HIGH
Conflicts
0

CVE-2026-47342

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache OFBiz
Provider severity
HIGH
Conflicts
0

CVE-2026-47341

Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47340

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4734

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules). This vulnerability is associated with program files imap.C‎. This issue affects modizer: before v4.3.

PUBLISHED
Vendor
yoyofr
Product
modizer
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47339

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47337

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
LOW
Conflicts
0

CVE-2026-47336

Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
LOW
Conflicts
0

CVE-2026-47335

Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47334

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47333

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
HIGH
Conflicts
0

CVE-2026-47332

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47331

Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
HIGH
Conflicts
0

CVE-2026-47330

Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
LOW
Conflicts
0

CVE-2026-4733

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

PUBLISHED
Vendor
ixray-team
Product
ixray-1.6-stcop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47329

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
LOW
Conflicts
0

CVE-2026-47328

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47327

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
LOW
Conflicts
0

CVE-2026-47326

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.

PUBLISHED
Vendor
Canonical
Product
Ubuntu Linux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47325

ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The application does not require or prompt users to change the password upon first login. This behavior allows attackers to easily guess or derive valid credentials, leading to unauthorized account access. The maintainers were notified early about this vulnerability but did not provide details regarding

PUBLISHED
Vendor
ProjectsAndPrograms
Product
school-management-system
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47324

ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other users’ browsers. Critically, when chained with CVE‑2025‑11661, which allows unauthenticated access to backend endpoints, this vulnerability can be exploited by a remote attacker without privileges to inject and execute

PUBLISHED
Vendor
ProjectsAndPrograms
Product
school-management-system
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47323

A flaw was found in Apache Camel. An unauthenticated attacker could inject Camel-internal headers via HTTP requests to CXF-RS or CXF-SOAP endpoints due to missing inbound filtering in the `HeaderFilterStrategy` implementations. This allows the attacker to override configured values when messages are forwarded to header-driven components like camel-exec or camel-file, potentially leading to remote code execution or arbitrary file writes.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, OpenShift Serverless, OpenShift Serverless, Red Hat Process Automation 7, OpenShift Serverless, OpenShift Serverless, OpenShift Serverless, OpenShift Serverless, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Fuse 7, Red Hat build of Apache Camel 4 for Quarkus 3, Apache Camel, Red Hat build of Apache Camel for Spring Boot 4, OpenShift Serverless, Red Hat build of Apache Camel for Spring Boot 4
Provider severity
CRITICAL
Conflicts
2

CVE-2026-47320

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

PUBLISHED
Vendor
Samsung Open Source
Product
rlottie
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4732

Out-of-bounds Read vulnerability in tildearrow furnace (‎extern/libsndfile-modified/src modules). This vulnerability is associated with program files flac.C‎. This issue affects furnace: before 0.7.

PUBLISHED
Vendor
tildearrow
Product
furnace
Provider severity
HIGH
Conflicts
0

CVE-2026-47319

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

PUBLISHED
Vendor
Samsung Open Source
Product
rlottie
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47318

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

PUBLISHED
Vendor
Samsung Open Source
Product
rlottie
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47317

Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

PUBLISHED
Vendor
Samsung Open Source
Product
Escargot
Provider severity
MEDIUM
Conflicts
0