A vulnerability classified as critical was found in open-metadata OpenMetadata up to 1.11.7. The affected element is an unknown function of the file /api/v1/ingestionPipelines. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-26010. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in ahdinosaur set-in up to 2.0.4 and classified as problematic. Impacted is an unknown function. The manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability is identified as CVE-2026-26021. The attack is only possible with local access. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in langgenius dify up to 1.12.x. This impacts an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-26023. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in Apple iOS and iPadOS up to 18.7.4. It has been declared as critical. Impacted is an unknown function of the component Backup File Handler. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2025-43537. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in python-pillow Pillow up to 12.1.0. It has been classified as critical. Impacted is an unknown function of the component PSD Image Parser. The manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-25990. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Apple macOS, iOS and iPadOS. It has been rated as critical. The affected element is an unknown function of the component HID Handler. Performing a manipulation results in memory corruption.
This vulnerability is identified as CVE-2025-46300. The attack may be carried out on the physical device. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Apple macOS, iOS and iPadOS. The impacted element is an unknown function of the component HID Handler. Executing a manipulation can lead to memory corruption.
This vulnerability is tracked as CVE-2025-46301. The physical device can be targeted for the attack. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Apple macOS, iOS and iPadOS. This affects an unknown function of the component HID Handler. The manipulation leads to memory corruption.
This vulnerability is listed as CVE-2025-46302. It is possible to launch the attack on the physical device. There is no available exploit.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Apple macOS, iOS and iPadOS. This impacts an unknown function of the component HID Handler. The manipulation results in memory corruption.
This vulnerability is cataloged as CVE-2025-46303. An attack on the physical device is feasible. There is no exploit available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Apple macOS, iOS and iPadOS. Affected is an unknown function of the component HID Handler. This manipulation causes memory corruption.
This vulnerability is registered as CVE-2025-46304. It is feasible to perform the attack on the physical device. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in libpng up to 1.6.54. It has been rated as critical. Affected is the function png_set_quantize of the component Low-level API. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is known as CVE-2026-25646. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in frangoteam FUXA up to 1.2.10. It has been declared as critical. This affects an unknown part of the component SCADA/HMI/Dashboard. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-25951. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in frangoteam FUXA up to 1.2.9. Affected is an unknown function of the component Heartbeat Refresh API. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-25893. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, was found in frangoteam FUXA up to 1.2.9. Affected by this issue is some unknown functionality of the component SCADA/HMI/Dashboard. The manipulation results in path traversal.
This vulnerability is known as CVE-2026-25895. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability has been found in frangoteam FUXA up to 1.2.9 and classified as problematic. This affects an unknown part of the component SCADA/HMI/Dashboard. This manipulation causes use of hard-coded cryptographic key
.
This vulnerability is handled as CVE-2026-25894. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in frangoteam FUXA up to 1.2.10. It has been classified as critical. This issue affects some unknown processing of the component SCADA/HMI/Dashboard. Performing a manipulation results in missing authorization.
This vulnerability was named CVE-2026-25939. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in frangoteam FUXA up to 1.2.10. It has been declared as critical. This affects an unknown function of the component SCADA/HMI/Dashboard. The manipulation results in authentication bypass by spoofing.
This vulnerability was named CVE-2026-25938. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in TP-Link Tapo C260 v1. Impacted is an unknown function of the component Requests Handler. The manipulation results in improper access controls.
This vulnerability is identified as CVE-2026-0653. The attack can be executed remotely. There is not any exploit available.