A vulnerability was found in Linux Kernel up to 6.12.80/6.18.21/6.19.11 and classified as critical. This affects the function queue_entity. The manipulation results in memory corruption.
This vulnerability is known as CVE-2026-43323. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.80/6.18.21/6.19.11. It has been classified as critical. This vulnerability affects the function btrfs_run_delayed_refs of the component btrfs. This manipulation causes infinite loop.
This vulnerability is handled as CVE-2026-43338. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.19.11. The impacted element is the function synchronize_irq. The manipulation leads to state issue.
This vulnerability is referenced as CVE-2026-43324. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.11. This affects the function usb_gadget_udc_reset. The manipulation results in denial of service.
This vulnerability is identified as CVE-2026-43327. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.21/6.19.11. Affected by this vulnerability is the function dcn401_init_hw. Performing a manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-43337. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.21/6.19.11. Affected by this issue is some unknown functionality of the component wifi. Performing a manipulation results in denial of service.
This vulnerability is identified as CVE-2026-43325. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.19.11. The impacted element is the function smp_cmd_pairing_req of the component Bluetooth. Such manipulation leads to channel accessible by non-endpoint.
This vulnerability is listed as CVE-2026-43334. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.19.11. This impacts the function kick_cpus_irq_workfn. Executing a manipulation can lead to deadlock.
This vulnerability is registered as CVE-2026-43326. The attack requires access to the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.19.11 and classified as critical. Affected by this vulnerability is the function permuted_state. The manipulation results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-43336. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability classified as critical has been found in ThimPress LearnPress Plugin up to 4.3.5 on WordPress. Affected by this vulnerability is the function add_to_cart of the component REST API Endpoint. The manipulation leads to authorization bypass.
This vulnerability is listed as CVE-2026-7648. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability has been found in unitecms Unlimited Elements for Elementor Plugin up to 2.0.7 on WordPress and classified as critical. This impacts the function normalizeAjaxInputData. The manipulation of the argument filter_search leads to sql injection.
This vulnerability is traded as CVE-2026-5486. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Alinto SOGo up to 5.12.6. Affected by this vulnerability is an unknown functionality. The manipulation of the argument c_password results in sql injection.
This vulnerability is reported as CVE-2026-46446. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability described as critical has been identified in joedolson My Calendar Plugin up to 3.7.9 on WordPress. Affected is an unknown function of the component POST Request Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-7525. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as problematic was found in smub Envira Gallery Plugin up to 1.12.4 on WordPress. Affected by this issue is the function update_gallery_data of the component REST API. The manipulation of the argument arrows results in cross site scripting.
This vulnerability is cataloged as CVE-2026-5361. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability identified as problematic has been detected in OpenStack Ironic. The impacted element is an unknown function. This manipulation causes incorrect behavior order.
The identification of this vulnerability is CVE-2026-44919. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.