A vulnerability was found in Craft CMS up to 4.10.0/5.5.1. It has been declared as problematic. This affects an unknown function of the component Store Management Section. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-25522. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of the argument filePath leads to path traversal.
This vulnerability is referenced as CVE-2026-2552. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
A vulnerability described as problematic has been identified in Wagtail up to 6.3.5/7.0.3/7.1.2/7.2.1/7.3rc1. Impacted is an unknown function of the component Preview Endpoint. Such manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-25517. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability identified as problematic has been detected in Kubernetes ingress-nginx up to 1.13.6/1.14.1. The affected element is an unknown function of the component Ingress Annotation Handler. This manipulation causes improper check for unusual conditions.
This vulnerability is registered as CVE-2026-24513. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in Kubernetes ingress-nginx up to 1.13.6/1.14.1. The impacted element is an unknown function. Such manipulation leads to allocation of resources.
This vulnerability is documented as CVE-2026-24514. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
Currently trending CVE - Hype Score: 3 - A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a ...
Currently trending CVE - Hype Score: 3 - Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the ...
A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches. [...]
A vulnerability classified as critical was found in Significant-Gravitas AutoGPT up to 0.6.33. The impacted element is the function aiohttp.ClientSession.get. Executing a manipulation can lead to server-side request forgery.
This vulnerability appears as CVE-2025-62616. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability has been found in Significant-Gravitas AutoGPT up to 0.6.33 and classified as critical. This affects the function urllib.request.urlopen. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2025-62615. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in ERPNext up to 15.88.1. It has been declared as problematic. Impacted is an unknown function of the component PDF File Parser. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2025-65924. It is possible to launch the attack remotely. No exploit is available.