,

Vulnerability Watch No36

🎞️ GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads
Anyone operating applications that process untrusted media with the affected GStreamer component should prioritize remediation. Crafted media can trigger memory reads outside the intended bounds, so systems accepting untrusted ASF, WMV, or WMA files deserve prompt attention.
CVE-2026-19389 affects the GStreamer gst-plugins-ugly ASF demuxer when parsing crafted ASF, WMV, or WMA files. Integer overflow and underflow vulnerabilities can bypass bounds checks and cause out-of-bounds heap reads, resulting in application crashes, denial of service, or limited information disclosure. The vulnerability is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD

💥 GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution
Operators of applications that decode untrusted WAV files with the affected GStreamer component should patch promptly. The potential for memory corruption and arbitrary code execution makes this more serious than a simple crash bug.
CVE-2026-19387 is a heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. A crafted WAV file can cause writes beyond the allocated output buffer, potentially leading to application crashes, denial of service, memory corruption, or arbitrary code execution. The vulnerability is rated HIGH with CVSS 7.6.
🔗 Read more 🔗
Source: NVD

🔓 Uasoft Badaso File API Permission Flaw Has Public Exploit
Anyone running Uasoft Badaso 3.0.0-alpha should treat this as urgent because public exploit material is already available. Until the project responds, reduce exposure to the affected File API and apply appropriate mitigations.
CVE-2026-19376 affects the File API in Uasoft Badaso 3.0.0-alpha, specifically ApiRequest::class in src/Routes/api.php, and leads to permission issues. The flaw can be attacked remotely, and an exploit has been publicly disclosed and may be used. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD

⚠️ ipTIME AX8004M Command Injection Has Public Exploit
Administrators of affected ipTIME AX8004M devices should prioritize remediation because public exploit material is available and the flaw is remotely reachable. With no vendor response reported, limiting access to the affected CGI endpoint is an important interim measure.
CVE-2026-19379 affects EFM ipTIME AX8004M 15.09.0 and causes OS command injection through the fname argument in /cgi/d.cgi. The attack can be initiated remotely, and the exploit has been publicly disclosed and may be utilized. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD

🛡️ Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management
Users and administrators with Kingston FURY CTRL RGB Control Software 2.0.65.0 should prioritize remediation, particularly on systems where untrusted local users may gain access. Public exploit availability raises the urgency even though exploitation requires a local attack path.
CVE-2026-19381 affects Kingston FURY CTRL RGB Control Software 2.0.65.0 through the NTIOLib_KSFX.sys driver and results in improper privilege management. The attack requires local access, and the exploit has been released publicly and may be used for attacks. The vulnerability is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

💉 Doctors Appointment System SQL Injection Has Public Exploit
Administrators running SourceCodester Simple Doctors Appointment System 1.0 should treat this as urgent because the SQL injection is remotely reachable and public exploit material exists. Reduce exposure to the affected endpoint and apply available remediation or mitigations promptly.
CVE-2026-19384 affects SourceCodester Simple Doctors Appointment System 1.0 through /admin/ajax.php?action=set_appointment, where manipulation of the ID argument causes SQL injection. The attack may be initiated remotely, and the exploit has been made publicly available and could be used for attacks. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD

🌐 adafap api-mcp Proxy Endpoint Exposed to Remote SSRF
Operators of affected api-mcp deployments should promptly restrict exposure to the Proxy API Endpoint and mitigate untrusted URL handling. The project uses rolling releases and has not responded to the report, so affected or fixed version details are not available from this entry.
CVE-2026-19374 affects adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06 in the customAxios function of app/api/proxy/route.ts. Manipulating the url argument in the Proxy API Endpoint leads to server-side request forgery, and the attack can be carried out remotely. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD

💣 UTT HiPER 1200GW Buffer Overflow Has Public Exploit
Administrators of UTT HiPER 1200GW devices up to 2.5.3-170306 should treat this as urgent because the flaw is remotely exploitable and public exploit material exists. With no vendor response reported, limiting access to the affected interface is an important immediate mitigation.
CVE-2026-19341 affects UTT HiPER 1200GW up to 2.5.3-170306 through the strcpy function in /goform/pptpSrvGlobalConfig. Manipulating the EncryptionMode argument causes a stack-based buffer overflow that can be exploited remotely, and the exploit has been publicly disclosed and may be used. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD