A vulnerability classified as problematic has been found in themefusion Avada Builder Plugin up to 3.15.2 on WordPress. This vulnerability affects the function fusion_get_svg_from_file of the component Shortcode Handler. The manipulation of the argument custom_svg leads to absolute path traversal.
This vulnerability is traded as CVE-2026-4782. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in themefusion Avada Builder Plugin up to 3.15.1 on WordPress. This affects the function product_order. Executing a manipulation can lead to sql injection.
This vulnerability appears as CVE-2026-4798. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as problematic has been reported in SUSE openSUSE Tumbleweed. Affected by this issue is some unknown functionality of the component csync2. Performing a manipulation results in time-of-check time-of-use.
This vulnerability is reported as CVE-2026-41051. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability labeled as problematic has been found in Checkmk up to 2.2.0/2.3.0p46/2.4.0p28 on Windows. Affected by this vulnerability is an unknown functionality of the component mk_mysql Agent Plugin. Such manipulation leads to uncontrolled search path.
This vulnerability is documented as CVE-2024-47091. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Hostinger Reach Plugin up to 1.3.8 on WordPress. Affected is the function handle_ajax_action. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2026-2515. Remote exploitation of the attack is possible. No exploit is available.
Educational tech firm Instructure reached a deal with hackers after a major Canvas breach exposed data stolen from schools and universities. Educational tech firm Instructure says it reached an agreement with the cybercrime group behind a major Canvas data theft, after attackers broke into its systems and threatened to publish stolen information from schools and […]
A vulnerability was found in Apache HTTP Server up to 2.4.66 and classified as problematic. Affected by this issue is some unknown functionality of the component mod_auth_digest. The manipulation results in observable timing discrepancy.
This vulnerability is identified as CVE-2026-33006. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been classified as problematic. This affects an unknown part of the component mod_authn_socache. This manipulation causes null pointer dereference.
This vulnerability is tracked as CVE-2026-33007. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been rated as critical. This issue affects some unknown processing of the component Module. Performing a manipulation results in http response splitting.
This vulnerability is cataloged as CVE-2026-33523. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Apache HTTP Server up to 2.4.66. This vulnerability affects unknown code of the component mod_proxy_ajp. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-33857. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Apache HTTP Server up to 2.4.66. This issue affects some unknown processing. Executing a manipulation can lead to improper null termination.
This vulnerability appears as CVE-2026-34032. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Apache HTTP Server up to 2.4.66. The affected element is an unknown function of the component mod_md. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-29168. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been declared as critical. Impacted is the function ajp_msg_check_header. Executing a manipulation can lead to buffer overflow.
The identification of this vulnerability is CVE-2026-28780. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been declared as problematic. This vulnerability affects unknown code of the component mod_dav_lock/mod_dav_svn. Such manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2026-29169. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.