4.8
CVE-2026-7739 - justdan96 tsMuxer hevc.cpp setFPS denial of service
A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::setFPS of the file /AFLplusplus/tsMuxer_prev/tsMuxer/hevc.cpp. This manipulation of the argument track_id causes denial of service. The attack requires local access. The exploit hasβ¦
2.5
CVE-2026-43864 - mutt: Mutt: Denial of Service via null pointer dereference in show_sig_summary
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
3.7
CVE-2026-43863 - mutt: Mutt: Remote Denial of Service via crafted input
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
3.7
CVE-2026-43862 - mutt: Mutt: Security bypass due to mishandled IMAP authentication
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
5.3
CVE-2026-7738 - puchunjie doc-tools-mcp MCP mcp-server.ts open_document path traversal
A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The manipulation of the argument filePath results in path traversal. The attack can be launched remotely. The β¦
5.3
CVE-2026-5335 - Magic Export & Import < 1.2.0 - Unauthenticated PII Disclosure
The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.
3.7
CVE-2026-43861 - mutt: Mutt: URL processing vulnerability due to improper null character handling
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
6.9
CVE-2026-7737 - osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remβ¦
3.7
CVE-2026-43860 - mutt: mutt: Authentication bypass due to IMAP CRAM-MD5 hash truncation
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
6.7
CVE-2026-20451 -
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504.