7.2
CVE-2026-38751 - Arbitrary File Upload in OpenSTAManager Module Update
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
7.8
CVE-2026-36365 - Local Code Execution via Insecure Functions in caesium-image-compressor
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp
6.1
CVE-2026-38669 -
wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.
7.5
CVE-2026-37459 - Integer Underflow in FRRouting Leads to Denial of Service via Crafted BGP UPDATE
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
6.5
CVE-2026-37458 -
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
9.8
CVE-2025-70067 - Assimp: Assimp: Buffer overflow in FBX Importer allows arbitrary code execution via crafted file.
Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation
7.5
CVE-2025-70069 - Assimp: Assimp: Denial of Service via FBXConverter.cpp and ConvertMeshMultiMaterial() method
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method
6.5
CVE-2025-70072 - Assimp: Assimp: Denial of Service via FBXConverter components
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components
5.9
CVE-2025-70071 - Assimp: Assimp: Denial of Service via FBXParser.cpp ParseVectorDataArray() function
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()
6.5
CVE-2025-70070 - Assimp: Assimp: Denial of Service via FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()