A vulnerability, which was classified as problematic, was found in crypto-x509 up to 1.25.8/1.26.1 on Go. This impacts an unknown function of the component Certificate Handler. The manipulation results in inefficient algorithmic complexity.
This vulnerability is known as CVE-2026-32281. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in crypto-x509 up to 1.25.8/1.26.1 on Go and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Certificate Handler. Such manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2026-32280. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in cmd-compile up to 1.25.8/1.26.1 on Go and classified as critical. This vulnerability affects unknown code. Executing a manipulation of the argument induction can lead to integer overflow.
This vulnerability is handled as CVE-2026-27143. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Apache Airflow up to 3.2.1. Affected by this vulnerability is an unknown functionality of the component KubernetesExecutor Command-Line Argument Handler. The manipulation results in information disclosure.
This vulnerability is known as CVE-2026-49298. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in cmd-compile up to 1.25.8/1.26.1 on Go. It has been classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in expected behavior violation.
This vulnerability was named CVE-2026-27144. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in cmd-go up to 1.25.8/1.26.1 on Go. This vulnerability affects unknown code of the component SWIG File Parser. Performing a manipulation results in trust boundary violation.
This vulnerability is reported as CVE-2026-27140. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in Apache Airflow up to 3.2.1. Affected by this vulnerability is an unknown functionality of the component Event Log Detail Endpoint. The manipulation leads to permission issues.
This vulnerability is referenced as CVE-2026-46764. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Apache Airflow up to 3.2.1. Affected by this issue is the function revoke_token of the component FabAuthManager/KeycloakAuthManager. The manipulation results in improper access controls.
This vulnerability is identified as CVE-2026-48726. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Apache Airflow up to 3.2.1. It has been declared as problematic. This impacts an unknown function of the component SMTP STARTTLS Connection Handler. Executing a manipulation can lead to improper certificate validation.
This vulnerability appears as CVE-2026-49267. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Apache Airflow up to 3.2.1. Affected is the function lstrip of the component JWT. Executing a manipulation can lead to authorization bypass.
The identification of this vulnerability is CVE-2026-45426. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Sergey AIWU Plugin up to 1.4.17 on WordPress. The affected element is an unknown function. Such manipulation leads to incorrect privilege assignment.
This vulnerability is referenced as CVE-2026-48879. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, has been found in ThimPress LearnPress Plugin up to 4.3.6 on WordPress. Impacted is an unknown function. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-48865. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in VeronaLabs WP Statistics Plugin up to 14.16.6 on WordPress. This issue affects some unknown processing. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-48839. The attack may be performed from remote. There is no available exploit.