A vulnerability identified as problematic has been detected in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2026-1972. The attack may be initiated remotely. In addition, an exploit is available.
The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website."
A vulnerability categorized as problematic has been discovered in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2026-1971. The attack can be launched remotely. Moreover, an exploit is present.
The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website."
A vulnerability was found in Edimax BR-6258n up to 1.18. It has been rated as problematic. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redirect. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2026-1970. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website."
A vulnerability was found in TeamViewer Remote, Tensor and One up to 15.74.4. It has been declared as problematic. This vulnerability affects unknown code. The manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-23572. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in YugabyteDB Anywhere. It has been classified as problematic. This affects an unknown part of the component LDAP Configuration Handler. The manipulation leads to insufficiently protected credentials.
This vulnerability is traded as CVE-2026-1966. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in OpenSolution Quick.Cart 6.7 and classified as problematic. Affected by this issue is some unknown functionality of the component User Password Handler. Executing a manipulation can lead to unprotected storage of credentials.
This vulnerability appears as CVE-2026-23797. The attack may be performed from remote. There is no available exploit.
A vulnerability has been found in OpenSolution Quick.Cart 6.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Session Identifier Handler. Performing a manipulation results in session fixiation.
This vulnerability is reported as CVE-2026-23796. The attack is possible to be carried out remotely. No exploit exists.
This week didn’t produce one big headline. It produced many small signals — the kind that quietly shape what attacks will look like next.
Researchers tracked intrusions that start in ordinary places: developer workflows, remote tools, cloud access, identity paths, and even routine user actions. Nothing looked dramatic on the surface. That’s the point. Entry is becoming less visible while impact
A vulnerability labeled as critical has been found in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2025-15555. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.
A vulnerability classified as critical was found in Langroid 0.53.4/0.53.15. This issue affects some unknown processing of the component TableChatAgent. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-25481. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in devcode-it openstamanager up to 2.9.8. Affected by this issue is some unknown functionality of the component Stampe Module. Executing a manipulation can lead to sql injection.
This vulnerability appears as CVE-2025-69215. The attack may be performed from remote. There is no available exploit.
A vulnerability has been found in ZenTao up to 21.7.6-85642 and classified as critical. The impacted element is the function fetchHook of the file module/webhook/model.php of the component Webhook Module. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-1884. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in WeKan up to 8.20 and classified as critical. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improper authorization.
This vulnerability is traded as CVE-2026-1892. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.