5.1

CVSS3.1

CVE-2026-34238 - ImageMagick: Integer overflow in despeckle operation causes heap buffer overflow on 32-bit builds

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write. This issue has been…

πŸ“… Published: April 13, 2026, 9:14 p.m. πŸ”„ Last Modified: April 13, 2026, 10:16 p.m.

7.5

CVSS3.1

CVE-2026-33908 - ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When …

πŸ“… Published: April 13, 2026, 9:06 p.m. πŸ”„ Last Modified: April 13, 2026, 10:16 p.m.

5.5

CVSS3.1

CVE-2026-33905 - ImageMagick has an Out-of-Bounds read via -sample operation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. T…

πŸ“… Published: April 13, 2026, 9:02 p.m. πŸ”„ Last Modified: April 13, 2026, 10:16 p.m.

5.1

CVSS4.0

CVE-2026-6220 - HummerRisk Video File Download URL ServerService.java ServerService.addServer server-side request f…

A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServer of the file ServerService.java of the component Video File Download URL Handler. Such manipulation of the argument streamIp leads to server-side request forgery. It is possible …

πŸ“… Published: April 13, 2026, 9 p.m. πŸ”„ Last Modified: April 13, 2026, 10:16 p.m.

5.5

CVSS3.1

CVE-2026-33902 - ImageMagick: Stack Overflow via Recursive FX Expression Parsing

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression. This is…

πŸ“… Published: April 13, 2026, 8:59 p.m. πŸ”„ Last Modified: April 13, 2026, 10:16 p.m.

7.5

CVSS3.1

CVE-2026-33901 - ImageMagick has a Heap Buffer Overflow via MVG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in ve…

πŸ“… Published: April 13, 2026, 8:56 p.m. πŸ”„ Last Modified: April 13, 2026, 9:16 p.m.

5.9

CVSS3.1

CVE-2026-33900 - ImageMagick has a Heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit bui…

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash…

πŸ“… Published: April 13, 2026, 8:50 p.m. πŸ”„ Last Modified: April 13, 2026, 10:16 p.m.

5.3

CVSS3.1

CVE-2026-33899 - ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-1…

πŸ“… Published: April 13, 2026, 8:46 p.m. πŸ”„ Last Modified: April 13, 2026, 9:16 p.m.

4.8

CVSS4.0

CVE-2026-6219 - aandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injection

A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly …

πŸ“… Published: April 13, 2026, 8:45 p.m. πŸ”„ Last Modified: April 13, 2026, 9:16 p.m.

5.4

CVSS3.1

CVE-2026-33740 - EspoCRM: Email importEml can import and delete another user's attachment by raw fileId

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parameter is used to fetch any attachment directly from…

πŸ“… Published: April 13, 2026, 8:37 p.m. πŸ”„ Last Modified: April 13, 2026, 9:16 p.m.
Total resulsts: 344716
Page 54 of 34,472
Β« previous page Β» next page
Filters