A vulnerability was found in PgBouncer up to 1.25.1. It has been classified as problematic. This affects an unknown function of the component Administration Console. The manipulation of the argument admin_users leads to missing authorization.
This vulnerability is documented as CVE-2026-6667. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability labeled as problematic has been found in PgBouncer up to 1.25.1. This affects an unknown part of the component Error Response Handler. Executing a manipulation of the argument SQLSTATE can lead to null pointer dereference.
This vulnerability is handled as CVE-2026-6666. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Devolutions Server up to 2025.3.16.0/2026.1.11.0. It has been classified as problematic. The impacted element is an unknown function of the component PAM Module. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-8407. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability marked as problematic has been reported in PgBouncer up to 1.25.1. This affects an unknown function of the component Network Packet Handler. This manipulation causes integer overflow.
The identification of this vulnerability is CVE-2026-6664. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in PgBouncer up to 1.25.1 and classified as critical. The impacted element is the function strlcat. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2026-6665. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Adobe Acrobat Reader up to 24.001.30356/26.001.21367 and classified as critical. Affected by this vulnerability is an unknown functionality of the component File Handler. Performing a manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability is identified as CVE-2026-34621. The attack can be initiated remotely. Additionally, an exploit exists.
The affected component should be upgraded.
A vulnerability was found in Open5GS up to 2.7.7 and classified as problematic. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference.
This vulnerability appears as CVE-2026-8252. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-8253. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been rated as problematic. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-8255. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Devs Palace ERP Online up to 4.0.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-8254. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.