A vulnerability, which was classified as critical, was found in langflow-ai Langflow up to 1.8.1. This impacts an unknown function of the component Public Flow Build Endpoint. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code.
The identification of this vulnerability is CVE-2026-33017. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in parse-server. This affects an unknown function of the component Deep Copy. Performing a manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability was named CVE-2026-32878. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Xen. The impacted element is an unknown function of the component Xenstored. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-23555. The attack can only be initiated within the local network. No exploit exists.
Applying a patch is advised to resolve this issue.
A vulnerability classified as critical has been found in Xen. The affected element is an unknown function of the component EPT. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-23554. The attack can only be done within the local network. There is not any exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability labeled as problematic has been found in Dahua NVR2-4KS3, XVR4232AN-I, T and XVR1B16H-I. This vulnerability affects unknown code. Executing a manipulation can lead to authentication bypass by primary weakness.
This vulnerability appears as CVE-2025-31703. The physical device can be targeted for the attack. There is no available exploit.
A vulnerability categorized as critical has been discovered in VMware Spring AI up to 1.0.3/1.1.2. Affected by this issue is some unknown functionality of the component MariaDBFilterExpressionConverter. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-22730. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in VMware Spring AI up to 1.0.3/1.1.2. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component AbstractFilterExpressionConverter. This manipulation causes injection.
This vulnerability is registered as CVE-2026-22729. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability has been found in alhadeff Writeprint Stylometry Plugin up to 0.1 on WordPress and classified as problematic. The impacted element is the function bjl_wprintstylo_comments_nav of the component GET Parameter Handler. Performing a manipulation of the argument p results in cross site scripting.
This vulnerability is identified as CVE-2026-3512. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A high-severity security flaw affecting default installations of Ubuntu Desktop versions 24.04 and later could be exploited to escalate privileges to the root level.
Tracked as CVE-2026-3888 (CVSS score: 7.8), the issue could allow an attacker to seize control of a susceptible system.
"This flaw (CVE-2026-3888) allows an unprivileged local attacker to escalate privileges to full root access