Trend Micro has patched two critical Apex One vulnerabilities that allow attackers to gain remote code execution (RCE) on vulnerable Windows systems. [...]
A Greek court sentenced the founder of the Intellexa Consortium and three associates to prison for their role in a sprawling spyware scandal that has dominated Greek headlines since it came to light in 2022.
A vulnerability classified as critical was found in Linux Kernel up to 6.1.160/6.6.120/6.12.65/6.18.5/6.19-rc5. Affected is the function bpf_prog_test_run_xdp. The manipulation results in improper update of reference count.
This vulnerability is cataloged as CVE-2026-22994. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.18.5/6.19-rc4. It has been declared as critical. Impacted is the function error_code of the component idpf. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-22993. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.66/6.18.6/6.19-rc5. It has been rated as critical. Affected is the function tegra_adma_terminate_all of the component Tegra ADMA Driver. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2025-71162. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.66/6.18.6/6.19-rc5. Affected by this vulnerability is the function j1939_xtp_rx_rts_session_active. Executing a manipulation can lead to improper update of reference count.
This vulnerability is handled as CVE-2026-22997. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.66/6.18.6/6.19-rc5. Affected by this issue is the function mlx5e_priv. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-22996. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.66/6.18.6/6.19-rc5. It has been declared as critical. This impacts an unknown function of the component dmaengine. Such manipulation leads to memory leak.
This vulnerability is traded as CVE-2025-71163. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.5/6.19-rc3/6.19-rc4. It has been rated as critical. The affected element is the function ublk_ctrl_start_dev of the component ublk. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-22995. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. It has been declared as critical. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn leads to improper authorization.
This vulnerability is traded as CVE-2025-15087. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.1. This vulnerability affects the function exfat_find of the component exfat. The manipulation results in improper update of reference count.
This vulnerability is identified as CVE-2025-68351. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability described as critical has been identified in Linux Kernel up to 6.17.11. This issue affects the function deferred_irq_workfn of the component sched_ext. Such manipulation leads to improper initialization.
This vulnerability is listed as CVE-2025-68333. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.60/6.17.10. This affects the function ipgre_header. Performing a manipulation results in state issue.
This vulnerability is known as CVE-2025-68340. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in Availability Booking Calendar 5.0. It has been declared as problematic. This affects an unknown part of the file index.php. Such manipulation of the argument name/plugin_sms_api_key/plugin_sms_country_code/uuid/title/country name leads to cross site scripting.
This vulnerability is documented as CVE-2023-48208. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in Jorani Leave Management System 1.0.2. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument Host results in weak password recovery.
This vulnerability is identified as CVE-2023-48205. The attack can be executed remotely. There is not any exploit available.
A vulnerability has been found in Availability Booking Calendar 5.0 and classified as problematic. This affects an unknown part of the component Reservations List. This manipulation causes csv injection.
This vulnerability is tracked as CVE-2023-48207. The attack is only possible within the local network. No exploit exists.
A vulnerability marked as problematic has been reported in GaatiTrack Courier Management System 1.0. The impacted element is an unknown function of the file login.php. This manipulation of the argument page causes cross site scripting.
This vulnerability is handled as CVE-2023-48206. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in sanluan PublicCMS 4.0.202302.e and classified as problematic. This impacts an unknown function of the file api/method/getHtml. Such manipulation of the argument appToken leads to information disclosure.
This vulnerability is documented as CVE-2023-48204. The attack can be executed remotely. There is not any exploit available.