A vulnerability marked as problematic has been reported in Medical Management System. Impacted is an unknown function of the component Password Reset Handler. The manipulation leads to weak password recovery.
This vulnerability is listed as CVE-2025-67437. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as problematic has been found in vercel turborepo up to 2.9.13. This issue affects some unknown processing. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is tracked as CVE-2026-45773. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in vercel turborepo up to 2.9.13999. This vulnerability affects unknown code. Performing a manipulation results in command injection.
This vulnerability is identified as CVE-2026-46508. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in cli up to 2.91.x. This affects an unknown part. Such manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is referenced as CVE-2026-45803. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in vercel turborepo, codemod and workspaces up to 2.9.13. It has been rated as problematic. Affected by this issue is some unknown functionality. This manipulation causes untrusted search path.
The identification of this vulnerability is CVE-2026-45772. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Apache Flink up to 1.20.3/2.0.1/2.1.1/2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TaskManagers. The manipulation results in code injection.
This vulnerability was named CVE-2026-35194. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Cloud Internal Integration Platform API. It has been classified as critical. Affected is an unknown function of the component API Endpoint. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-2031. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Nodemailer smtp_server up to 3.18.2 and classified as problematic. This impacts the function SMTPStream._write in the library lib/smtp-stream.js. Executing a manipulation can lead to denial of service.
This vulnerability is handled as CVE-2026-38728. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Oinone Pamirs 7.0.0 and classified as problematic. This affects an unknown function of the component XML Parser. Performing a manipulation results in xml external entity reference.
This vulnerability is known as CVE-2026-39053. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as problematic, was found in Silabs Simplicity SDK. The impacted element is an unknown function. Such manipulation leads to insufficient entropy.
This vulnerability is traded as CVE-2025-14972. The attack can be executed directly on the physical device. There is no exploit available.
A vulnerability, which was classified as critical, has been found in TONYC Imager up to 1.030 on Perl. The affected element is the function Imager::File::GIF of the file imgif.c. This manipulation causes out-of-bounds write.
This vulnerability appears as CVE-2026-8669. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical was found in vim up to 9.2.0478. Impacted is the function Vimuntar of the file runtime/autoload/tar.vim of the component Archive File Handler. The manipulation results in os command injection.
This vulnerability is reported as CVE-2026-46483. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Oinone Pamirs 7.0.0. This issue affects the function CommandHelper.executeCommands. The manipulation leads to command injection.
This vulnerability is documented as CVE-2026-39054. The attack requires being on the local network. There is not any exploit available.
A vulnerability described as critical has been identified in Oinone Pamirs up to 7.0.0. This vulnerability affects the function ScriptRunner.run. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-39052. The attack requires access to the local network. No exploit is available.
A vulnerability marked as problematic has been reported in websockets ws up to 8.20.0. This affects the function websocket.close. Performing a manipulation of the argument Reason results in uninitialized resource.
This vulnerability is cataloged as CVE-2026-45736. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in vorbis-tools 1.4.3. Affected by this issue is the function remotethread of the file remote.c of the component ogg123. Such manipulation leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2026-34253. The attack may be performed from remote. There is no available exploit.