A vulnerability identified as critical has been detected in YML for Yandex Market Plugin up to 5.0.25 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in code injection.
This vulnerability is cataloged as CVE-2025-14545. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Japan Computer Emergency Response Team Coordination Center Emocheck. This affects an unknown part. Such manipulation leads to uncontrolled search path. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is listed as CVE-2026-28704. The attack must be carried out locally. There is no available exploit.
A vulnerability was found in YITH WooCommerce Wishlist Plugin up to 4.12.x on WordPress. It has been rated as critical. Affected by this issue is the function save_title of the file /wishlist/ of the component AJAX Handler. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2026-4432. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in OpenSSL up to 3.4.0. This affects an unknown part of the component RFC7250 Raw Public Key Handler. Performing a manipulation results in missing report of error condition.
This vulnerability is known as CVE-2024-12797. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability has been found in D-Link DIR-513 1.10 and classified as critical. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2026-6014. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in Tenda AC9 15.03.02.13 and classified as critical. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2026-6015. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in Tenda AC9 15.03.02.13. It has been classified as critical. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-6016. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in Tenda i6 1.0.0.7(2204). It has been classified as critical. Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-6024. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. It has been declared as critical. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection.
This vulnerability is referenced as CVE-2026-6025. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, was found in IBM Langflow Desktop up to 1.8.2. The affected element is an unknown function of the component Langflow. Executing a manipulation can lead to deserialization.
This vulnerability is handled as CVE-2026-3357. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in IBM Tivoli Netcool Impact up to 7.1.0.37. This vulnerability affects unknown code. The manipulation results in sensitive information in log files.
This vulnerability is cataloged as CVE-2026-4788. The attack must be initiated from a local position. There is no exploit available.
The affected component should be upgraded.
A vulnerability classified as problematic was found in Gravity Forms Plugin up to 2.9.30 on WordPress. The impacted element is the function GFCommon::send_json of the component Content-Type Handler. Executing a manipulation of the argument form_ids can lead to cross site scripting.
This vulnerability appears as CVE-2026-4406. The attack may be performed from remote. There is no available exploit.
A vulnerability has been found in wpchill Download Monitor Plugin up to 5.1.10 on WordPress and classified as problematic. The impacted element is the function actions_handler of the file class-dlm-downloads-path.php. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2026-4401. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.