A vulnerability has been found in PaperCut Hive up to 2.1.x and classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in sensitive information in log files.
This vulnerability is cataloged as CVE-2026-7824. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in PaperCut NG and MF up to 25.0.10. Affected is an unknown function of the component Account Synchronization Component. Such manipulation leads to absolute path traversal.
This vulnerability is listed as CVE-2026-6418. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Saleswonder WebinarIgnition Plugin up to 4.08.253 on WordPress. This impacts an unknown function. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2026-40797. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability classified as critical was found in PaperCut NG and MF up to 24.1.8/25.0.9. This affects an unknown function. The manipulation results in time-of-check time-of-use.
This vulnerability is identified as CVE-2026-6180. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in wpmudev Forminator Forms Plugin up to 1.52.1 on WordPress. The impacted element is the function file_path of the component File Upload. The manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-5192. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability described as problematic has been identified in edge22 GenerateBlocks Plugin up to 2.2.0 on WordPress. The affected element is an unknown function of the file /wp-json/generateblocks/v1/dynamic-tag-replacements of the component REST Endpoint. Executing a manipulation of the argument ID can lead to authorization bypass.
The identification of this vulnerability is CVE-2026-3454. The attack may be launched remotely. There is no exploit available.
A vulnerability labeled as critical has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element is the function is_safe_path of the file src/code_mcp/server.py of the component MCP File Handler. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-7811. It is possible to launch the attack remotely. Furthermore, an exploit is available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability marked as critical has been reported in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the function git_operation of the file src/code_mcp/server.py of the component MCP Tool. Performing a manipulation of the argument operation results in command injection.
This vulnerability is identified as CVE-2026-7812. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability marked as critical has been reported in wpmudev Forminator Forms Plugin up to 1.52.0 on WordPress. Impacted is an unknown function. Performing a manipulation results in authorization bypass.
This vulnerability was named CVE-2026-2729. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as critical has been found in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The manipulation of the argument ids leads to sql injection.
This vulnerability is listed as CVE-2026-7822. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in roxnor ElementsKit Elementor Addons Plugin up to 3.8.2 on WordPress. It has been rated as critical. Affected by this issue is the function Live_Action::reset. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-4362. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection.
This vulnerability is cataloged as CVE-2026-7823. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.11. This impacts an unknown function of the component iommupt. Executing a manipulation can lead to privilege escalation.
This vulnerability is tracked as CVE-2026-31735. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.12.80/6.18.21/6.19.11. It has been classified as critical. This affects the function mtk_ppe: of the component net. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-31736. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability has been found in Linux Kernel up to 6.18.21/6.19.11 and classified as problematic. This affects the function is_bpf_migration_disabled of the file trampoline.c of the component sched_ext. Performing a manipulation results in privilege escalation.
This vulnerability is known as CVE-2026-31734. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.21/6.19.11. Affected by this issue is the function gpiochip_add_data_with_key of the component gpio. Such manipulation leads to double free.
This vulnerability is traded as CVE-2026-31732. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.81/6.18.21/6.19.11. The impacted element is the function mark_direct_dispatch of the file kernel/sched/ext.c. The manipulation results in state issue.
This vulnerability was named CVE-2026-31733. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.6.133/6.12.80/6.18.21/6.19.11 and classified as critical. This vulnerability affects the function fastrpc_init_create_static_process of the component Misc. Executing a manipulation can lead to double free.
This vulnerability is handled as CVE-2026-31730. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.