Posts of last 24 hours
A vulnerability classified as problematic was found in Axllent Mailpit up to 1.30.4. This affects the function readData of the file internal/smtpd/smtpd.go of the component smtpd. Such manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-67447. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/393891
A vulnerability classified as critical has been found in Apple Container up to 1.1.x. Affected by this issue is some unknown functionality. This manipulation causes buffer overflow.
The identification of this vulnerability is CVE-2026-64773. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/393890
A vulnerability described as problematic has been identified in code100x CMS 1.0. Affected by this vulnerability is an unknown functionality of the file src/middleware.ts of the component Middleware. The manipulation results in information disclosure.
This vulnerability was named CVE-2026-52021. The attack may be performed from remote. There is no available exploit.
https://vuldb.com/vuln/393889
A vulnerability marked as critical has been reported in Tor Project Tor. Affected is the function relay_send_command_from_edge of the component Conflux Switch Cell. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-77641. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/393888
A vulnerability labeled as problematic has been found in Axllent Mailpit up to 1.30.3. This impacts the function imaging.Decode of the file server/apiv1/thumbnails.go of the component Thumbnail Handler. Executing a manipulation can lead to resource consumption.
This vulnerability is handled as CVE-2026-67446. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/393887
A vulnerability identified as critical has been detected in Apple swift-nio-ssh up to 0.14.0. This affects an unknown function. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2026-43798. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/393886
A vulnerability categorized as critical has been discovered in libvips up to 8.18.2. The impacted element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c of the component PPM Image Handler. Such manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2026-70654. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/393885
A vulnerability was found in libvips up to 8.18.2. It has been rated as problematic. The affected element is the function scanline_read_old of the file libvips/foreign/radiance.c of the component Radiance RLE decoder. This manipulation causes heap-based buffer overflow.
This vulnerability appears as CVE-2026-70653. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/393884
A vulnerability was found in libvips up to 8.18.2. It has been declared as critical. Impacted is the function vips_foreign_save_uhdr_set_raw_hdr of the file libvips/foreign/uhdrsave.c of the component Uhdrsave. The manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2026-70652. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/393883
A vulnerability was found in DiceBear up to 9.4.2. It has been classified as critical. This issue affects the function addRotate of the file packages/@dicebear/core/src/utils/svg.ts of the component SVG Generation. The manipulation of the argument rotate leads to injection.
This vulnerability is documented as CVE-2026-68921. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/393882