| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions. |
| Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
| Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1. |
| Windows Graphics Component Information Disclosure Vulnerability |
| Microsoft Office Security Feature Bypass Vulnerability |
| Microsoft Excel Remote Code Execution Vulnerability |
| Microsoft Excel Spoofing Vulnerability |
| Microsoft Word Security Feature Bypass Vulnerability |
| External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
| Microsoft Office Graphics Remote Code Execution Vulnerability |
| Microsoft Office Trust Center Spoofing Vulnerability |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability |
| Microsoft Excel Security Feature Bypass Vulnerability |
| Microsoft Office OneNote Remote Code Execution Vulnerability |
| Microsoft Outlook Remote Code Execution Vulnerability |
| GDI+ Remote Code Execution Vulnerability |
| Microsoft Outlook Remote Code Execution Vulnerability |
| Microsoft Excel Information Disclosure Vulnerability |
| Microsoft ActiveX Remote Code Execution Vulnerability |
| Microsoft Office Security Feature Bypass Vulnerability |