A vulnerability described as problematic has been identified in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read.
This vulnerability is handled as CVE-2026-2659. It is possible to launch the attack on the local host. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability marked as problematic has been reported in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unknown function of the component Multiple Endpoints. Performing a manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2026-2658. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
The project was informed of the problem early through an issue report but has not responded yet.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The list of vulnerabilities is as follows -
CVE-2026-2441 (CVSS score: 8.8) - A use-after-free vulnerability in Google Chrome that could allow a remote attacker to potentially exploit heap
A vulnerability labeled as problematic has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-2657. An attack has to be approached locally. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability identified as problematic has been detected in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use after free.
This vulnerability appears as CVE-2026-2656. The attack requires local access. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability categorized as problematic has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::operator of the file include/chaiscript/chaiscript_defines.hpp. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-2655. The attack requires a local approach. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.