libheif Heap Buffer Overflow Vulnerability (GHSA-g89c-p67h-r497)
libheif versions through v1.23.1 contain a critical heap buffer overflow in image scaling code, exploitable via crafted AVIF files. The flaw can…
libheif versions through v1.23.1 contain a critical heap buffer overflow in image scaling code, exploitable via crafted AVIF files. The flaw can…
A critical heap buffer overflow in libheif (CVSS v4 9.5) exploited via crafted AVIF images leads to remote code execution in Next.js…
A heap buffer overflow in libheif's image scaling code (all versions through v1.23.1) allows remote code execution when processing crafted AVIF files.…
CVE-2020-2551 is a critical remote code execution vulnerability in Oracle WebLogic Server's IIOP component. It has been exploited in the wild and…
CVE-2017-10271 is a critical remote code execution vulnerability in Oracle WebLogic Server's WLS-WSAT component. It has been exploited for years and remains…
CVE-2020-14882 is a critical remote code execution vulnerability in Oracle WebLogic Server's Console component. It has been widely exploited in the wild…
CVE-2020-14883 is a critical remote code execution vulnerability in Oracle WebLogic Server's Console component. It is often chained with CVE-2020-14882 and remains…
A popular WordPress page builder plugin. Versions up to 4.2.1 are vulnerable to unauthenticated PHP upload and RCE (CVE-2026-32475). Patched in 4.2.2.
FUXA is an open-source, web-based SCADA/HMI software for operational technology (OT) and industrial automation. It is affected by CVE-2026-25895, a critical vulnerability…
High-severity WordPress core vulnerability enabling remote code execution via malicious Postscript file upload by Author-level users. Affects versions 4.7 to 7.0. Patched…