5.5

CVSS3.1

CVE-2026-40183 - ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 8:44 p.m.

9.8

CVSS3.1

CVE-2026-22563 - Command Injection via Improper Input Validation in Ubiquiti UniFi Play Devices

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Pl…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2026-22562 - Path Traversal Vulnerability Allowing Remote File Write on Ubiquiti UniFi Play Devices

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-22566 - Improper Access Control in Ubiquiti UniFi Play Devices Enables Unauthorized Retrieval of WiFi Crede…

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-22565 -

An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update Un…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2026-22564 - Unauthorized SSH Access via Improper Access Control on UniFi Play Devices

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitig…

📅 Published: April 13, 2026, 9:28 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

6.2

CVSS3.1

CVE-2026-40169 - ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.

📅 Published: April 13, 2026, 9:25 p.m. 🔄 Last Modified: April 17, 2026, 8:45 p.m.

6.9

CVSS4.0

CVE-2026-6224 - nocobase plugin-workflow-javascript Vm.js createSafeConsole sandbox

A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initia…

📅 Published: April 13, 2026, 9:15 p.m. 🔄 Last Modified: April 14, 2026, 4:33 p.m.

5.1

CVSS3.1

CVE-2026-34238 - ImageMagick: Integer overflow in despeckle operation causes heap buffer overflow on 32-bit builds

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write. This issue has been…

📅 Published: April 13, 2026, 9:14 p.m. 🔄 Last Modified: April 17, 2026, 9:22 p.m.

7.5

CVSS3.1

CVE-2026-33908 - ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When …

📅 Published: April 13, 2026, 9:06 p.m. 🔄 Last Modified: April 17, 2026, 8:45 p.m.
Total resulsts: 346717
Page 250 of 34,672
« previous page » next page
Filters