A vulnerability categorized as problematic has been discovered in Microsoft Enterprise Security Token Service. Affected is an unknown function. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-40379. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Linux Kernel up to 6.19.8. It has been declared as problematic. This impacts the function mlx5e_reset_txqsq_cc_pc of the component mlx5e. Such manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2026-43466. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.77/6.18.18/6.19.8. It has been rated as critical. This vulnerability affects the function do_user_addr_fault. This manipulation causes denial of service.
The identification of this vulnerability is CVE-2026-43467. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.166/6.6.129/6.12.77/6.18.18/6.19.8. Impacted is the function work_queue. Performing a manipulation results in deadlock.
This vulnerability is identified as CVE-2026-43468. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.8. The affected element is the function rpcrdma_post_recvs. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-43469. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability described as critical has been identified in jackc pgx up to 5.9.1 on Go. This affects an unknown function. The manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-41889. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability described as problematic has been identified in absinthe-graphql absinthe_plug up to 1.2.0. Affected by this vulnerability is the function absinthe_plug in the library lib/absinthe/plug/graphiql.ex. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-42794. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
A vulnerability identified as problematic has been detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion.
This vulnerability was named CVE-2026-8257. The attack needs to be approached locally. In addition, an exploit is available.
It is suggested to install a patch to address this issue.
A vulnerability classified as problematic was found in elie222 inbox-zero up to 2.29.2. This impacts an unknown function of the component Cleaner Email Stream Endpoint. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-42865. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in elixir-ecto postgrex up to 0.22.1 and classified as critical. Impacted is the function handle_connect in the library lib/postgrex/notifications.ex. Such manipulation of the argument channel leads to sql injection.
This vulnerability is listed as CVE-2026-32687. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.18/6.19.8. This issue affects the function iavf_reset_task. This manipulation causes use after free.
The identification of this vulnerability is CVE-2026-43447. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.