5.5

CVSS3.1

CVE-2026-40311 - ImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing values

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions…

📅 Published: April 13, 2026, 9:36 p.m. 🔄 Last Modified: April 17, 2026, 8:43 p.m.

5.5

CVSS3.1

CVE-2026-40310 - ImageMagick: Heap out-of-bounds write in JP2 encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and …

📅 Published: April 13, 2026, 9:32 p.m. 🔄 Last Modified: April 17, 2026, 8:44 p.m.

5.5

CVSS3.1

CVE-2026-40183 - ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 8:44 p.m.

9.8

CVSS3.1

CVE-2026-22563 - Command Injection via Improper Input Validation in Ubiquiti UniFi Play Devices

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Pl…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2026-22562 - Path Traversal Vulnerability Allowing Remote File Write on Ubiquiti UniFi Play Devices

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-22566 - Improper Access Control in Ubiquiti UniFi Play Devices Enables Unauthorized Retrieval of WiFi Crede…

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-22565 -

An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update Un…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2026-22564 - Unauthorized SSH Access via Improper Access Control on UniFi Play Devices

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitig…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

6.2

CVSS3.1

CVE-2026-40169 - ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.

📅 Published: April 13, 2026, 9:25 p.m. 🔄 Last Modified: April 17, 2026, 8:45 p.m.

6.9

CVSS4.0

CVE-2026-6224 - nocobase plugin-workflow-javascript Vm.js createSafeConsole sandbox

A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initia…

📅 Published: April 13, 2026, 9:15 p.m. 🔄 Last Modified: April 14, 2026, 4:33 p.m.
Total resulsts: 346107
Page 189 of 34,611
« previous page » next page
Filters