6.1

CVSS3.1

CVE-2026-39956 - jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks…

📅 Published: April 13, 2026, 10:10 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7

CVSS4.0

CVE-2026-4786 - Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

📅 Published: April 13, 2026, 9:52 p.m. 🔄 Last Modified: April 17, 2026, 3:18 p.m.

6.2

CVSS3.1

CVE-2026-33947 - jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a …

📅 Published: April 13, 2026, 9:50 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

6.2

CVSS3.1

CVE-2026-40312 - ImageMagick: Off-by-One in MSL decoder could result in crash

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.

📅 Published: April 13, 2026, 9:43 p.m. 🔄 Last Modified: April 17, 2026, 8:42 p.m.

5.5

CVSS3.1

CVE-2026-40311 - ImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing values

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions…

📅 Published: April 13, 2026, 9:36 p.m. 🔄 Last Modified: April 17, 2026, 8:43 p.m.

5.5

CVSS3.1

CVE-2026-40310 - ImageMagick: Heap out-of-bounds write in JP2 encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and …

📅 Published: April 13, 2026, 9:32 p.m. 🔄 Last Modified: April 17, 2026, 8:44 p.m.

5.5

CVSS3.1

CVE-2026-40183 - ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 8:44 p.m.

9.8

CVSS3.1

CVE-2026-22563 - Command Injection via Improper Input Validation in Ubiquiti UniFi Play Devices

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Pl…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2026-22562 - Path Traversal Vulnerability Allowing Remote File Write on Ubiquiti UniFi Play Devices

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-22566 - Improper Access Control in Ubiquiti UniFi Play Devices Enables Unauthorized Retrieval of WiFi Crede…

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.
Total resulsts: 345253
Page 106 of 34,526
« previous page » next page
Filters